ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24356
fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP.

fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake packet. This "fast reconnect" avoids having to wait for a session timeout (up to ~90s) until a new connection is established. Even a 1-byte UDP packet just containing the fastd packet type header can trigger a much larger handshake packet (~150 bytes of UDP payload). Including IPv4 and UDP headers, the resulting amplification factor is roughly 12-13. By sending data packets with a spoofed source address to fastd instances reachable on the internet, this amplification of UDP traffic might be used to facilitate a Distributed Denial of Service attack. This vulnerability is fixed in v23.

NVD description · AI analysis pending
6.9<1%
  • fastd project fastd
CVE-2020-27638
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

NVD description · AI analysis pending
7.52%
  • fastd project fastd
  • fastd project debian linux
  • fastd project fedora