CVE-2026-54345
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 28, 2026 · Last modified: Jul 28, 2026 · CWE-191 · CWE-770
Not enough EPSS history yet.
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.
- github.comhttps://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311
- github.comhttps://github.com/gopacket/gopacket/releases/tag/v1.6.1
- github.comhttps://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5
- github.comhttps://github.com/gopacket/gopacket/security/advisories/GHSA-6r28-9ppf-4hj5