Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c21aea77 by Sylvain Beucler at 2026-07-15T10:25:28+02:00
CVE-2026-48689/fastnetmon: bookworm,bullseye not-affected

7836db2091522831c703c5a9dc3f39be9f12def5 introduces dynamic buffers,
and the "Why +1" comment.

- - - - -
14f9e828 by Sylvain Beucler at 2026-07-15T10:26:35+02:00
CVE-2026-48688/fastnetmon: bookworm,bullseye not-affected

d4420c49908d33e837a26ea849339fcfa3f36c2d adds support for
MP_REACH_NLRI, and the "TODO: we should add sanity checks".

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37956,15 +37956,21 @@ CVE-2026-48690 (FastNetMon Community Edition through 
1.2.9 contains an integer o
 CVE-2026-48689 (FastNetMon Community Edition through 1.2.9 contains an 
off-by-one heap ...)
        {DSA-6375-1}
        - fastnetmon 1.2.9-1 (bug #1138646)
+       [bookworm] - fastnetmon <not-affected> (Vulnerable code introduced 
later)
+       [bullseye] - fastnetmon <not-affected> (Vulnerable code introduced 
later)
        NOTE: 
https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48689-dynamic-buffer-off-by-one
        NOTE: https://github.com/pavel-odintsov/fastnetmon/pull/1051
        NOTE: 
https://github.com/pavel-odintsov/fastnetmon/commit/fa80390ed446f887ca6fa39c9e5b6fff8846e822
 (v1.2.9)
+       NOTE: Introduced by: 
https://github.com/pavel-odintsov/fastnetmon/commit/7836db2091522831c703c5a9dc3f39be9f12def5
 (v1.2.6)
 CVE-2026-48688 (FastNetMon Community Edition through 1.2.9 contains multiple 
out-of-bo ...)
        {DSA-6375-1}
        - fastnetmon 1.2.9-1 (bug #1138646)
+       [bookworm] - fastnetmon <not-affected> (Vulnerable code introduced 
later)
+       [bullseye] - fastnetmon <not-affected> (Vulnerable code introduced 
later)
        NOTE: 
https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48688-bgp-mp-reach-nlri-ipv6
        NOTE: 
https://github.com/pavel-odintsov/fastnetmon/commit/04e26ac2e0861efe7a50f3c3fd27e57f840aa4a3
 (v1.2.9)
        NOTE: https://github.com/pavel-odintsov/fastnetmon/pull/1055
+       NOTE: 
https://github.com/pavel-odintsov/fastnetmon/commit/d4420c49908d33e837a26ea849339fcfa3f36c2d
 (v1.2.6)
 CVE-2026-48687 (FastNetMon Community Edition through 1.2.9 contains an OS 
command inje ...)
        {DSA-6375-1}
        - fastnetmon 1.2.9-1 (unimportant; bug #1138646)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b6ed47b3d9cdc43ed8dc5a6285c92c85643433db...14f9e828eb7786433fa345475ea08d5765710de8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b6ed47b3d9cdc43ed8dc5a6285c92c85643433db...14f9e828eb7786433fa345475ea08d5765710de8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to