Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Integer Overflow in FastNetMon BGP AS_PATH Encoder Causes Heap Buffer Overflow |
Wed, 27 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow via BGP AS_PATH Overwrite in FastNetMon Community Edition | |
| Weaknesses | CWE-120 |
Wed, 27 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 | |
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow via BGP AS_PATH Overwrite in FastNetMon Community Edition | |
| First Time appeared |
Pavel-odintsov
Pavel-odintsov fastnetmon |
|
| Weaknesses | CWE-120 CWE-190 |
|
| Vendors & Products |
Pavel-odintsov
Pavel-odintsov fastnetmon |
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(uint32_t)' and stores it in a uint8_t field (line 600-605). Since uint8_t can only hold values 0-255, an AS_PATH containing more than 63 ASNs (2 + 64*4 = 258 > 255) causes silent truncation. The truncated length is used for buffer sizing, while the actual data written is the full untruncated amount, resulting in a heap buffer overflow. Similarly, the path_segment_length field at line 621 is also uint8_t, truncating with more than 255 ASNs. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T20:37:43.097Z
Reserved: 2026-05-22T00:00:00.000Z
Link: CVE-2026-48691
Updated: 2026-05-27T20:34:54.076Z
Status : Modified
Published: 2026-05-26T17:16:53.670
Modified: 2026-06-17T10:55:11.290
Link: CVE-2026-48691
No data.
OpenCVE Enrichment
Updated: 2026-05-28T00:00:14Z