gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.
References
| Link | Resource |
|---|---|
| https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311 | Patch |
| https://github.com/gopacket/gopacket/releases/tag/v1.6.1 | Release Notes |
| https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5 | Exploit Third Party Advisory |
| https://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-28 17:16
Updated : 2026-08-05 19:04
NVD link : CVE-2026-54345
Mitre link : CVE-2026-54345
CVE.ORG link : CVE-2026-54345
JSON object : View
Products Affected
gopacket
- gopacket
