CVE-2026-48685
published 2026-05-26CVE-2026-48685: FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.29%
21.2th percentile
FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly identifies when extended_length_bit is set and sets length_of_length_field to 2, but then reads only a single byte for the attribute value length (attribute_value_length = value[2] at line 173). Per RFC 4271 Section 4.3, when the Extended Length bit is set, the Attribute Length field is two octets and the value should be read as a 16-bit big-endian integer from value[2] and value[3]. As a result, any attribute longer than 255 bytes has its length silently truncated to the low byte (e.g., 300 bytes = 0x012C is read as 0x2C = 44 bytes). The remaining 256 bytes are then misinterpreted as subsequent attributes, causing cascading parse failures and potential out-of-bounds memory access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pavel-odintsov | fastnetmon | <= 1.2.9 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes [fedora-all]
bugzilla·2026-05-28·CVSS 6.5
CVE-2026-48685 [MEDIUM] CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes [fedora-all]
CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes [epel-all]
bugzilla·2026-05-28·CVSS 6.5
CVE-2026-48685 [MEDIUM] CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes [epel-all]
CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes
bugzilla·2026-05-26·CVSS 6.5
CVE-2026-48685 [MEDIUM] CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes
CVE-2026-48685 fastnetmon: out-of-bounds memory access due to incorrect parsing of BGP path attributes
FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly identifies when extended_length_bit is set and sets length_of_length_field to 2, but then reads only a single byte for the attribute value length (attribute_value_length = value[2] at line 173). Per RFC 4271 Section 4.3, when the Extended Length bit is set, the Attribute Length field is two octets and the value should be read as a 16-bit big-endian integer from value[2] and value[3]. As a result, any attribute longer than 255 bytes has its length silently tr
2026-05-26
Published