CVE-2026-54332

NameCVE-2026-54332
Descriptiongopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-github-gopacket-gopacket (PTS)bookworm1.0.0-1vulnerable
forky, sid, trixie1.3.0-2vulnerable
gopacket (PTS)bullseye1.1.19-1vulnerable
bookworm1.1.19-3vulnerable
forky, sid, trixie1.1.19-6.2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-gopacket-gopacketsource(unstable)(unfixed)
gopacketsource(unstable)(unfixed)

Notes

https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563
Fixed by: https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc (v1.6.1)

Search for package or bug name: Reporting problems