The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to libpcap 1.10.7.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet. | |
| Title | OOBR in rpcap client in libpcap before 1.10.7 | |
| Weaknesses | CWE-126 CWE-1288 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Tcpdump
Published:
Updated: 2026-09-05T18:51:57.956Z
Reserved: 2026-07-29T13:32:44.322Z
Link: CVE-2026-18238
No data.
Status : Received
Published: 2026-09-05T19:16:55.477
Modified: 2026-09-05T19:16:55.477
Link: CVE-2026-18238
No data.
OpenCVE Enrichment
Updated: 2026-09-05T21:00:05Z