CVE-2026-54345

MEDIUM

gopacket < 1.6.1 - Diameter AVP Integer Underflow Denial of Service

Title source: manual
STIX 2.1

Description

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

Scores

CVSS v4 6.9
EPSS 0.0039
EPSS Percentile 31.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-191 CWE-770
Status published
Products (2)
gopacket/gopacket 0 - 1.6.1Go
gopacket/gopacket < 1.6.1
Published Jul 28, 2026
Tracked Since Jul 28, 2026