UBUNTU-CVE-2026-54332

Source
https://ubuntu.com/security/CVE-2026-54332
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-54332
Upstream
Published
2026-07-28T17:16:00Z
Modified
2026-08-06T22:15:23Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

References

Affected packages

Ubuntu:16.04:LTS
gopacket

Package

Name
gopacket
Purl
pkg:deb/ubuntu/gopacket?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.10-1
1.1.11-1
1.1.11-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-google-gopacket-dev",
            "binary_version": "1.1.11-2"
        },
        {
            "binary_name": "golang-gopacket-dev",
            "binary_version": "1.1.11-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
Ubuntu:18.04:LTS
gopacket

Package

Name
gopacket
Purl
pkg:deb/ubuntu/gopacket?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.12-2
1.1.13-1
1.1.14-1
1.1.14-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-google-gopacket-dev",
            "binary_version": "1.1.14-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
Ubuntu:20.04:LTS
gopacket

Package

Name
gopacket
Purl
pkg:deb/ubuntu/gopacket?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.14-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-google-gopacket-dev",
            "binary_version": "1.1.14-3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
Ubuntu:22.04:LTS
gopacket

Package

Name
gopacket
Purl
pkg:deb/ubuntu/gopacket?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.19-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-google-gopacket-dev",
            "binary_version": "1.1.19-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
Ubuntu:24.04:LTS
golang-github-gopacket-gopacket

Package

Name
golang-github-gopacket-gopacket
Purl
pkg:deb/ubuntu/golang-github-gopacket-gopacket?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0-1
1.2.0-1
1.2.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-gopacket-gopacket-dev",
            "binary_version": "1.2.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
gopacket

Package

Name
gopacket
Purl
pkg:deb/ubuntu/gopacket?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.19-3
1.1.19-4
1.1.19-6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-google-gopacket-dev",
            "binary_version": "1.1.19-6"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
Ubuntu:26.04:LTS
golang-github-gopacket-gopacket

Package

Name
golang-github-gopacket-gopacket
Purl
pkg:deb/ubuntu/golang-github-gopacket-gopacket?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.3.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-gopacket-gopacket-dev",
            "binary_version": "1.3.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"
gopacket

Package

Name
gopacket
Purl
pkg:deb/ubuntu/gopacket?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.19-6.2
1.1.19-6.2build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "golang-github-google-gopacket-dev",
            "binary_version": "1.1.19-6.2build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-54332.json"