<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Fastnetmon on CVE Alert &amp; Security Feed</title><link>https://cvealert.net/products/fastnetmon/</link><description>Recent content in Fastnetmon on CVE Alert &amp; Security Feed</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 26 May 2026 19:16:28 +0000</lastBuildDate><atom:link href="https://cvealert.net/products/fastnetmon/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48689</title><link>https://cvealert.net/posts/cve-2026-48689/</link><pubDate>Tue, 26 May 2026 19:16:28 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-48689/</guid><description>FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form &amp;lsquo;if (offset + length &amp;gt; maximum_internal_storage_size + 1)&amp;rsquo; instead of the correct &amp;lsquo;if (offset + length &amp;gt; maximum_internal_storage_size)&amp;rsquo;. This allows writing exactly one byte past the end of the heap-allocated buffer. The class is used pervasively in BGP message encoding/decoding, NetFlow template processing, and Flow Spec NLRI construction. An attacker who can send network traffic (NetFlow, sFlow, IPFIX, or BGP) to a FastNetMon instance can trigger this overflow, potentially achieving arbitrary code execution by corrupting heap metadata. Notably, the append_byte() method uses the correct bounds check, confirming the inconsistency.</description></item></channel></rss>