Home / mailings [USN-8429-1] FastNetMon vulnerabilities
Posted on 16 June 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8429-1
June 15, 2026
fastnetmon vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in FastNetMon.
Software Description:
- fastnetmon: High-performance DDoS detector
Details:
It was discovered that FastNetMon incorrectly validated prefix lengths when
decoding BGP NLRI data. A remote attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48686)
It was discovered that FastNetMon incorrectly sanitized input in the
Juniper router integration plugin. An attacker could possibly use this
issue to execute arbitrary commands. (CVE-2026-48687)
It was discovered that FastNetMon incorrectly handled buffer bounds checks
when processing network traffic. A remote attacker could possibly use this
issue to cause a denial of service or execute arbitrary code. This issue
only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48689)
It was discovered that FastNetMon incorrectly handled encoding the BGP
AS_PATH attribute. A remote attacker could possibly use this issue to cause
a denial of service or execute arbitrary code. This issue only affected
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48691)
It was discovered that FastNetMon incorrectly validated IP address input in
the Juniper router integration plugin. An attacker could possibly use this
issue to inject arbitrary router configuration commands. (CVE-2026-48694)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
fastnetmon 1.2.8+git20250911-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
fastnetmon 1.2.6-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
fastnetmon 1.1.4-1ubuntu0.1~esm1
Available with Ubuntu Pro
After a standard system update you need to restart fastnetmon to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8429-1
CVE-2026-48686, CVE-2026-48687, CVE-2026-48689, CVE-2026-48691,
CVE-2026-48694
--===============5921911117891317166==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
