Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94323.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94323
Upstream
Published
2026-07-28T17:16:51Z
Modified
2026-09-08T05:27:28Z
Summary
CVE-2026-54332 affecting package telegraf 1.31.0-28
Details

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

References

Affected packages

Azure Linux:3 / telegraf

Package

Name
telegraf
Purl
pkg:rpm/azure-linux/telegraf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.31.0-28

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94323.json"