Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security issues have been discovered in FastNetMon, a fast DDoS analyzer: TLS connections were insufficently validated and malformed Netflow/sFlow traffic could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 1.2.9-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6375-1
Several security issues were fixed in FastNetMon.. ========================================================================== Ubuntu Security Notice USN-8429-1 June 15, 2026 fastnetmon vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in FastNetMon. Software Description: - fastnetmon: High-performance DDoS detector Details: It was discovered that FastNetMon incorrectly validated prefix lengths when decoding BGP NLRI data. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48686) It was discovered that FastNetMon incorrectly sanitized input in the Juniper router integration plugin. An attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-48687) It was discovered that FastNetMon incorrectly handled buffer bounds checks when processing network traffic. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48689) It was discovered that FastNetMon incorrectly handled encoding the BGP AS_PATH attribute. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48691) It was discovered that FastNetMon incorrectly validated IP address input in the Juniper router integration plugin. An attacker could possibly use this issue to inject arbitrary router configuration commands. (CVE-2026-48694) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS fastnetmon 1.2.8+git20250911-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS fastnetmon 1.2.6-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS fastnetmon 1.1.4-1ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart fastnetmon to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8429-1 CVE-2026-48686, CVE-2026-48687, CVE-2026-48689, CVE-2026-48691, CVE-2026-48694 . Security issues in FastNetMon fixed for Ubuntu versions; critical updates available for DDoS detector.. DDoS detection, FastNetMon security, Ubuntu updates, command execution risk. . Severity: Critical. LinuxSecurity.com Team
Two security issues have been discovered in FastNetMon, a fast DDoS analyzer: Malformed Netflow/sFlow traffic could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5837-1
Get the latest Linux and open source security news straight to your inbox.