|
|
Log in / Subscribe / Register

Ubuntu alert USN-8429-1 (fastnetmon)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8429-1] FastNetMon vulnerabilities
Date:  Tue, 16 Jun 2026 00:18:08 +0000
Message-ID:  <E1wZHVI-0004YM-Ek@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8429-1 June 15, 2026 fastnetmon vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in FastNetMon. Software Description: - fastnetmon: High-performance DDoS detector Details: It was discovered that FastNetMon incorrectly validated prefix lengths when decoding BGP NLRI data. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48686) It was discovered that FastNetMon incorrectly sanitized input in the Juniper router integration plugin. An attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-48687) It was discovered that FastNetMon incorrectly handled buffer bounds checks when processing network traffic. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48689) It was discovered that FastNetMon incorrectly handled encoding the BGP AS_PATH attribute. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48691) It was discovered that FastNetMon incorrectly validated IP address input in the Juniper router integration plugin. An attacker could possibly use this issue to inject arbitrary router configuration commands. (CVE-2026-48694) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS fastnetmon 1.2.8+git20250911-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS fastnetmon 1.2.6-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS fastnetmon 1.1.4-1ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart fastnetmon to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8429-1 CVE-2026-48686, CVE-2026-48687, CVE-2026-48689, CVE-2026-48691, CVE-2026-48694


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmowldsACgkQcpJm3tlz hgGjZg/+JBCAIUZWoaqS0SDCPkbM08lbTBhTrYZApvS/OQYZDWt3hziv5KytJsfC SlRww14ZDvDrZj25X8yEDS+ckqjZ2Bm/QNZx1H5+DDNHDYUnYkEv4UnV1/70xXX7 dN4bpuIuubTpRThEmnH3LCzt/vbph7Q/fGkFszBPUCZ2reHAYWjPMz3PEl+ONFGL N6YnnBSoEV/F8uuLt6biu1ufN7t5hy3wZL73CT2lSouNnvdS/0qLxc0nB3flWfG+ iXGQvkaXQfnNwvluX4JlZQSohfq2/vu9PZsC7KSgAHhLjnoH8IjsGYTLhsqKxPgV WQXxRW3105d8pN9ol2viGO+VeP/q2YfMFWBHSu4o6H0m4eLNooe55XrdQmNnUT73 ZzU47KxJV04uJNu8eFXLYi8l23yYWHbi/8gZZ5MhD04CqnahvjFdE7XHphuf79Kf FZBhbdcZSF5c66SAN8cN4qEkR2HxvMzwvczWKGbVvg0jOH5pUzuqUGBi7Hj2FNNn 3L1C1vI75RCrKZxtsc/74O1iT2mLQccAB9QWvfe8Ph6r0EOzDVPAfh1SNScNt68S Uce3GSpwqI8qvQGppK/4xdxUWKkmO36fcXYFnSCG8d++edm26OHJ3ffS01KE7hI/ iMSxa17z81Vbd3znFxaRO+9hNHELa+EvDpCD8jnsWyhYNLyvG+g= =O6TJ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds