Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54332

Опубликовано: 28 июл. 2026
Источник: debian
EPSS Низкий

Описание

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-gopacket-gopacketunfixedpackage
golang-github-gopacket-gopacketpostponedbookwormpackage
golang-github-gopacket-gopacketpostponedbullseyepackage
gopacketunfixedpackage
gopacketpostponedbookwormpackage
gopacketpostponedbullseyepackage

Примечания

  • https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563

  • Fixed by: https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc (v1.6.1)

EPSS

Процентиль: 35%
0.00429
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 дней назад

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

CVSS3: 7.5
nvd
11 дней назад

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

github
11 дней назад

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

EPSS

Процентиль: 35%
0.00429
Низкий