What is CVE-2026-54345?
An integer underflow vulnerability exists in the Diameter AVP decoder of the gopacket library (version 1.6.0 and earlier). An attacker can craft a malicious packet with a manipulated AVP Length field, causing an underflow when subtracting the fixed header size and potentially leading to memory corruption or information disclosure. Users should upgrade to the latest patched version immediately.
Azərbaycanca: gopacket kitabxanasında (1.6.0 və əvvəlki versiyalar) Diameter AVP decoder-də tam ədəd daşması zəifliyi aşkarlanıb. Təcavüzkar xüsusi hazırlanmış paketlə AVP Length sahəsini manipulyasiya edərək mənfi uzunluq hesablaya bilər ki, bu da potensial oxuma-yazma əməliyyatlarına səbəb olur. İstifadəçilərə dərhal ən son versiyaya yenilənmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which component of gopacket does CVE-2026-54345 affect?
The vulnerability affects the Diameter AVP decoder component of the gopacket library.
What can an attacker achieve by exploiting this vulnerability?
An attacker can potentially achieve memory corruption or information disclosure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.