CVE-2026-48688

EUVD-2026-31844
FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads after attribute memory block.' The function casts raw pointers to structure types without verifying sufficient data exists (line 158), uses the attacker-controlled length_of_next_hop field to determine memcpy size (line 181), and computes prefix_length by dereferencing a pointer calculated from multiple attacker-controlled offsets without bounds validation (line 189). The prefix_length is then used to calculate number_of_bytes_required_for_prefix which becomes a memcpy length (line 202) with no check against remaining buffer size.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.21%
Affected Products (NVD)
VendorProductVersion
pavel-odintsovfastnetmon
𝑥
≤ 1.2.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fastnetmon
bookworm
1.2.4-2+deb12u1
fixed
bookworm (security)
1.2.4-2+deb12u1
fixed
bullseye
not-affected
forky
1.2.9-1
fixed
sid
1.2.9-1
fixed
trixie
1.2.9-0+deb13u1
fixed
trixie (security)
1.2.9-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fastnetmon
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage