<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:gopacket:gopacket:*:*:*:*:*:go:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agopacketgopacketgo/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 10:41:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agopacketgopacketgo/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-54332: Unbounded Memory Allocation in GoPacket sFlow Decoder</title><link>https://feed.craftedsignal.io/briefs/2026-08-gopacket-dos/</link><pubDate>Tue, 11 Aug 2026 10:41:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-gopacket-dos/</guid><description>A vulnerability in the GoPacket sFlow ExtendedGatewayFlow decoder allows unauthenticated remote attackers to trigger a massive memory allocation, resulting in a Denial of Service.</description><content:encoded><![CDATA[<p>CVE-2026-54332 affects the sFlow ExtendedGatewayFlow decoder component within the GoPacket library. The vulnerability stems from an unbounded memory allocation issue that occurs during the processing of malformed sFlow UDP packets. Specifically, a remote attacker can send a crafted 104-byte UDP datagram that triggers the decoder to attempt a memory allocation of up to 16 GiB. Because the allocation occurs before the packet structure is fully validated, an unauthenticated attacker can exhaust system memory by sending a single, small packet to any service utilizing the vulnerable decoder. This condition results in an unauthenticated remote Denial of Service (DoS) impact. Defenders should prioritize patching any software or network appliances that include the GoPacket library and process sFlow traffic.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to a complete Denial of Service for the affected application or service. Given that the impact is memory exhaustion (OOM), the target process will likely crash immediately. This vulnerability is particularly dangerous for network infrastructure components and security monitoring platforms that rely on GoPacket for high-speed packet ingestion and decoding, as it enables an attacker to knock out critical monitoring or routing nodes with minimal bandwidth expenditure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all internal software or third-party appliances utilizing the GoPacket library and update to the patched version immediately.</li>
<li>Review network configurations to restrict sFlow traffic to trusted sources, preventing untrusted external actors from reaching the vulnerable decoder.</li>
<li>Monitor for abnormal process crashes or memory utilization spikes on systems responsible for processing UDP-based telemetry.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>