勘弁してほしい。104バイトで最大16GiBを確保させる。 CVE-2026-54332は、GoPacketのsFlow ExtendedGatewayFlow decoderが攻撃者指定値を無制限にmakeへ渡し、104-byte UDP datagramだけで認証不要のremote DoSを起こせる問題。小さな入力でメモリを吹き飛ばす、嫌な非対称性だ。 ¥sFlowを受けている組織は、直接依存だけでなくtransitive dependencyまで見た方がいい。#セキュリティ ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54332
Post summary
CVE‑2026‑54332 is a remote DoS flaw in GoPacket’s sFlow ExtendedGatewayFlow decoder that lets an attacker trigger a memory blow‑up with a 104‑byte UDP packet without authentication.
