DEBIAN-CVE-2026-54332

Source
https://security-tracker.debian.org/tracker/CVE-2026-54332
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-54332
Upstream
Published
2026-07-28T17:16:51Z
Modified
2026-09-01T16:06:52Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

References

Affected packages

Debian:12
golang-github-gopacket-gopacket

Package

Name
golang-github-gopacket-gopacket
Purl
pkg:deb/debian/golang-github-gopacket-gopacket?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0-1
1.2.0-1
1.2.0-2
1.3.0-1
1.3.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json"
gopacket

Package

Name
gopacket
Purl
pkg:deb/debian/gopacket?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.19-3
1.1.19-4
1.1.19-5
1.1.19-6
1.1.19-6.1
1.1.19-6.2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json"
Debian:13
golang-github-gopacket-gopacket

Package

Name
golang-github-gopacket-gopacket
Purl
pkg:deb/debian/golang-github-gopacket-gopacket?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.3.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json"
gopacket

Package

Name
gopacket
Purl
pkg:deb/debian/gopacket?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.19-6.2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json"
Debian:14
golang-github-gopacket-gopacket

Package

Name
golang-github-gopacket-gopacket
Purl
pkg:deb/debian/golang-github-gopacket-gopacket?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.3.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json"
gopacket

Package

Name
gopacket
Purl
pkg:deb/debian/gopacket?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.19-6.2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54332.json"