Back

MEDIUM

Double-free in libpcap before 1.10.5 with remote packet capture support.

Published Aug 30, 2024

Description

In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns. This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block. A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400.

Affected products

Remediation

Vendor solution

Upgrade to libpcap 1.10.5.

Red Hat statement

This vulnerability is classified as Moderate severity rather than Important because while it involves a double-free condition that can lead to undefined behavior, the exploitability is generally constrained by the specific conditions under which the vulnerability can be triggered. The vulnerability arises in the handling of memory allocation and deallocation within a specific internal function (sock_initaddress()) during the remote packet capture setup, which is not commonly exposed to untrusted inputs or frequent use in most applications. Additionally, triggering the double-free condition typically requires precise control over the function's execution flow, limiting the practicality of exploitation.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Tcpdump
Published Aug 30, 2024
Updated Sep 3, 2024
Reserved Apr 11, 2024
CISA Vulnrichment
Updated Sep 3, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 31, 2024