[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-48689/fastnetmon: bookworm,bullseye not-affected
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Wed Jul 15 09:26:56 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c21aea77 by Sylvain Beucler at 2026-07-15T10:25:28+02:00
CVE-2026-48689/fastnetmon: bookworm,bullseye not-affected
7836db2091522831c703c5a9dc3f39be9f12def5 introduces dynamic buffers,
and the "Why +1" comment.
- - - - -
14f9e828 by Sylvain Beucler at 2026-07-15T10:26:35+02:00
CVE-2026-48688/fastnetmon: bookworm,bullseye not-affected
d4420c49908d33e837a26ea849339fcfa3f36c2d adds support for
MP_REACH_NLRI, and the "TODO: we should add sanity checks".
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37956,15 +37956,21 @@ CVE-2026-48690 (FastNetMon Community Edition through 1.2.9 contains an integer o
CVE-2026-48689 (FastNetMon Community Edition through 1.2.9 contains an off-by-one heap ...)
{DSA-6375-1}
- fastnetmon 1.2.9-1 (bug #1138646)
+ [bookworm] - fastnetmon <not-affected> (Vulnerable code introduced later)
+ [bullseye] - fastnetmon <not-affected> (Vulnerable code introduced later)
NOTE: https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48689-dynamic-buffer-off-by-one
NOTE: https://github.com/pavel-odintsov/fastnetmon/pull/1051
NOTE: https://github.com/pavel-odintsov/fastnetmon/commit/fa80390ed446f887ca6fa39c9e5b6fff8846e822 (v1.2.9)
+ NOTE: Introduced by: https://github.com/pavel-odintsov/fastnetmon/commit/7836db2091522831c703c5a9dc3f39be9f12def5 (v1.2.6)
CVE-2026-48688 (FastNetMon Community Edition through 1.2.9 contains multiple out-of-bo ...)
{DSA-6375-1}
- fastnetmon 1.2.9-1 (bug #1138646)
+ [bookworm] - fastnetmon <not-affected> (Vulnerable code introduced later)
+ [bullseye] - fastnetmon <not-affected> (Vulnerable code introduced later)
NOTE: https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48688-bgp-mp-reach-nlri-ipv6
NOTE: https://github.com/pavel-odintsov/fastnetmon/commit/04e26ac2e0861efe7a50f3c3fd27e57f840aa4a3 (v1.2.9)
NOTE: https://github.com/pavel-odintsov/fastnetmon/pull/1055
+ NOTE: https://github.com/pavel-odintsov/fastnetmon/commit/d4420c49908d33e837a26ea849339fcfa3f36c2d (v1.2.6)
CVE-2026-48687 (FastNetMon Community Edition through 1.2.9 contains an OS command inje ...)
{DSA-6375-1}
- fastnetmon 1.2.9-1 (unimportant; bug #1138646)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b6ed47b3d9cdc43ed8dc5a6285c92c85643433db...14f9e828eb7786433fa345475ea08d5765710de8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b6ed47b3d9cdc43ed8dc5a6285c92c85643433db...14f9e828eb7786433fa345475ea08d5765710de8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260715/c7277e7b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list