CVE-2026-48690

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_pkthdr_t)) + sizeof(fastnetmon_pcap_file_header_t)' using unsigned int (32-bit) arithmetic. With max_captured_packet_size=1500 and sizeof(fastnetmon_pcap_pkthdr_t)=16, each packet requires approximately 1516 bytes. If buffer_size_in_packets exceeds approximately 2,832,542, the multiplication overflows, resulting in a much smaller allocation than expected. Subsequent write_packet() calls then write past the allocated buffer, causing heap corruption. The buffer_size_in_packets value is derived from the ban_details_records_count configuration parameter, which is parsed using atoi() with no overflow checking.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*

History

27 May 2026, 14:34

Type Values Removed Values Added
References () https://github.com/pavel-odintsov/fastnetmon - () https://github.com/pavel-odintsov/fastnetmon - Product
References () https://github.com/pavel-odintsov/fastnetmon/blob/master/src/packet_storage.hpp - () https://github.com/pavel-odintsov/fastnetmon/blob/master/src/packet_storage.hpp - Product
References () https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48690-packet-storage-integer-overflow - () https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48690-packet-storage-integer-overflow - Third Party Advisory
First Time Pavel-odintsov
Pavel-odintsov fastnetmon
CPE cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*

26 May 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE CWE-122
CWE-190

26 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 17:16

Updated : 2026-05-27 14:34


NVD link : CVE-2026-48690

Mitre link : CVE-2026-48690

CVE.ORG link : CVE-2026-48690


JSON object : View

Products Affected

pavel-odintsov

  • fastnetmon
CWE
CWE-122

Heap-based Buffer Overflow

CWE-190

Integer Overflow or Wraparound