7.5

CVE-2026-88357

nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and can cause process termination in UBSan-instrumented builds or on strict-alignment architectures, leading to denial of service.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.467
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-1335 Incorrect Bitwise Shift of Integer

An integer value is specified to be shifted by a negative amount or an amount greater than or equal to the number of bits contained in the value causing an unexpected or indeterminate result.

https://github.com/ntop/nDPI/issues/3213
https://github.com/utoni/nDPI/commit/6ce1280c52ed52a97332c3fe58fd2b47b867ec6e
https://github.com/utoni/nDPI/commit/8fc3b439920021a77165f8aee4f81b25bc88629e
https://github.com/utoni/nDPI/commit/694231bb43ff21f452fbc2b53fcf6cdc9a99f75f
https://github.com/utoni/nDPI/commit/6698f14bf6025394a537fe23f413cf79e9d13594
https://github.com/ntop/nDPI/pull/3231