CVE-2026-54345
Medium
Elevated severity or exploit probability.
CVSS base
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
0.8%
54.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-191
Published 2026-07-28 · modified 2026-08-05
Description
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.
Affected
References
- https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311
- https://github.com/gopacket/gopacket/releases/tag/v1.6.1
- exploit https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5
- exploit https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5