What is CVE-2026-65819?
CVE-2026-65819: A vulnerability in the gopacket library up to version 1.7.0 allows crafted packets to bypass validation of lengths and offsets against packet buffers in multiple layer decoders. This affects Go applications using `DecodingLayerParser` or `DecodeFromBytes` for packet processing. Users should update to the latest version or apply security patches.
Azərbaycanca: CVE-2026-65819: gopacket kitabxanasının 1.7.0 versiyasına qədər olan layer decoder-lərdə, xüsusi hazırlanmış şəbəkə paketləri emal edilərkən, uzunluq və ofset kimi dəyərlərin buffer ölçüsü ilə düzgün yoxlanılmaması səbəbindən zəiflik mövcuddur. Bu, `DecodingLayerParser` və ya `DecodeFromBytes` funksiyaları vasitəsilə paket analizi aparan Go tətbiqlərinə təsir edə bilər. İstifadəçilər kitabxananı ən son versiyaya yeniləməli və ya təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which gopacket functions are affected by CVE-2026-65819?
The vulnerability is triggered in Go applications using the `DecodingLayerParser` or `DecodeFromBytes` functions for packet processing.
What is the recommended mitigation for CVE-2026-65819?
Users should update the gopacket library to the latest version or apply security patches.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.