CVE-2026-48685

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly identifies when extended_length_bit is set and sets length_of_length_field to 2, but then reads only a single byte for the attribute value length (attribute_value_length = value[2] at line 173). Per RFC 4271 Section 4.3, when the Extended Length bit is set, the Attribute Length field is two octets and the value should be read as a 16-bit big-endian integer from value[2] and value[3]. As a result, any attribute longer than 255 bytes has its length silently truncated to the low byte (e.g., 300 bytes = 0x012C is read as 0x2C = 44 bytes). The remaining 256 bytes are then misinterpreted as subsequent attributes, causing cascading parse failures and potential out-of-bounds memory access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*

History

27 May 2026, 14:23

Type Values Removed Values Added
References () https://github.com/pavel-odintsov/fastnetmon - () https://github.com/pavel-odintsov/fastnetmon - Product
References () https://github.com/pavel-odintsov/fastnetmon/blob/master/src/bgp_protocol.hpp - () https://github.com/pavel-odintsov/fastnetmon/blob/master/src/bgp_protocol.hpp - Product
References () https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48685-bgp-extended-length - () https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48685-bgp-extended-length - Third Party Advisory
First Time Pavel-odintsov
Pavel-odintsov fastnetmon
CPE cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*

26 May 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-130

26 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 16:16

Updated : 2026-05-27 14:23


NVD link : CVE-2026-48685

Mitre link : CVE-2026-48685

CVE.ORG link : CVE-2026-48685


JSON object : View

Products Affected

pavel-odintsov

  • fastnetmon
CWE
CWE-130

Improper Handling of Length Parameter Inconsistency