Aller au contenu

Fiche vulnérabilité

CVE-2026-54332 : faille élevée gopacket gopacket (CVSS 7.5)

Description

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
28 juil. 2026
Dernière mise à jour
5 août 2026

Produits concernés

  • gopacket gopacket

Références

Rechercher une autre vulnérabilité dans la base CVE