Double-free in libpcap before 1.10.5 with remote packet capture support.
Published Aug 30, 2024
4.4
MEDIUMCVSS 3.1
EPSS 0.24%
Description
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns. This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block. A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400.
Affected products
-
- Version 1.10.xStatusaffectedConstraints<=1.10.4
- Version 1.8.xStatusaffectedConstraints-
- Version 1.9.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Tcpdump Group | Libpcap | unaffected |
|
No data.
Red Hat Enterprise Linux 10
libpcap
Not affected
Red Hat Enterprise Linux 6
libpcap
Out of support scope
Red Hat Enterprise Linux 7
libpcap
Out of support scope
Red Hat Enterprise Linux 8
libpcap
Not affected
Red Hat Enterprise Linux 9
libpcap
Not affected
Red Hat OpenShift Container Platform 4
rhcos
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libpcap | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libpcap | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libpcap | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libpcap | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libpcap | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | rhcos | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to libpcap 1.10.5.
Red Hat statement
This vulnerability is classified as Moderate severity rather than Important because while it involves a double-free condition that can lead to undefined behavior, the exploitability is generally constrained by the specific conditions under which the vulnerability can be triggered. The vulnerability arises in the handling of memory allocation and deallocation within a specific internal function (sock_initaddress()) during the remote packet capture setup, which is not commonly exposed to untrusted inputs or frequent use in most applications. Additionally, triggering the double-free condition typically requires precise control over the function's execution flow, limiting the practicality of exploitation.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 3, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.24% (0.00242) | 13.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.22% (0.00220) | 12.36th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00050) | 12.67th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00043) | 10.81th | v3 (v2023.03.01) |
| Aug 31, 2024 | 0.04% (0.00043) | 9.54th | v3 (v2023.03.01) |
References (6)
- https://access.redhat.com/security/cve/CVE-2023-7256 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2308783 Issue Tracking
- https://github.com/the-tcpdump-group/libpcap/commit/262e4f34979872d822ccedf9f318ed89c4d31c03 patch
- https://github.com/the-tcpdump-group/libpcap/commit/2aa69b04d8173b18a0e3492e0c8f2f7fabdf642d patch
- https://nvd.nist.gov/vuln/detail/CVE-2023-7256
- https://www.cve.org/CVERecord?id=CVE-2023-7256
Change history (0)
No recorded changes yet.