Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c21aea77 by Sylvain Beucler at 2026-07-15T10:25:28+02:00
CVE-2026-48689/fastnetmon: bookworm,bullseye not-affected
7836db2091522831c703c5a9dc3f39be9f12def5 introduces dynamic buffers,
and the "Why +1" comment.
- - - - -
14f9e828 by Sylvain Beucler at 2026-07-15T10:26:35+02:00
CVE-2026-48688/fastnetmon: bookworm,bullseye not-affected
d4420c49908d33e837a26ea849339fcfa3f36c2d adds support for
MP_REACH_NLRI, and the "TODO: we should add sanity checks".
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37956,15 +37956,21 @@ CVE-2026-48690 (FastNetMon Community Edition through
1.2.9 contains an integer o
CVE-2026-48689 (FastNetMon Community Edition through 1.2.9 contains an
off-by-one heap ...)
{DSA-6375-1}
- fastnetmon 1.2.9-1 (bug #1138646)
+ [bookworm] - fastnetmon <not-affected> (Vulnerable code introduced
later)
+ [bullseye] - fastnetmon <not-affected> (Vulnerable code introduced
later)
NOTE:
https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48689-dynamic-buffer-off-by-one
NOTE: https://github.com/pavel-odintsov/fastnetmon/pull/1051
NOTE:
https://github.com/pavel-odintsov/fastnetmon/commit/fa80390ed446f887ca6fa39c9e5b6fff8846e822
(v1.2.9)
+ NOTE: Introduced by:
https://github.com/pavel-odintsov/fastnetmon/commit/7836db2091522831c703c5a9dc3f39be9f12def5
(v1.2.6)
CVE-2026-48688 (FastNetMon Community Edition through 1.2.9 contains multiple
out-of-bo ...)
{DSA-6375-1}
- fastnetmon 1.2.9-1 (bug #1138646)
+ [bookworm] - fastnetmon <not-affected> (Vulnerable code introduced
later)
+ [bullseye] - fastnetmon <not-affected> (Vulnerable code introduced
later)
NOTE:
https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48688-bgp-mp-reach-nlri-ipv6
NOTE:
https://github.com/pavel-odintsov/fastnetmon/commit/04e26ac2e0861efe7a50f3c3fd27e57f840aa4a3
(v1.2.9)
NOTE: https://github.com/pavel-odintsov/fastnetmon/pull/1055
+ NOTE:
https://github.com/pavel-odintsov/fastnetmon/commit/d4420c49908d33e837a26ea849339fcfa3f36c2d
(v1.2.6)
CVE-2026-48687 (FastNetMon Community Edition through 1.2.9 contains an OS
command inje ...)
{DSA-6375-1}
- fastnetmon 1.2.9-1 (unimportant; bug #1138646)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b6ed47b3d9cdc43ed8dc5a6285c92c85643433db...14f9e828eb7786433fa345475ea08d5765710de8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b6ed47b3d9cdc43ed8dc5a6285c92c85643433db...14f9e828eb7786433fa345475ea08d5765710de8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits