OOBR and OOBW in libpcap before 1.10.7
Published Sep 5, 2026
8.7
HIGHCVSS 3.1
EPSS 0.11%
Description
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.
Affected products
-
- Version 0StatusaffectedConstraints<1.10.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Tcpdump Group | Libpcap | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 10
libpcap
Affected
Red Hat Enterprise Linux 6
libpcap
Affected
Red Hat Enterprise Linux 7
libpcap
Affected
Red Hat Enterprise Linux 8
libpcap
Affected
Red Hat Enterprise Linux 9
libpcap
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libpcap | Affected | n/a |
| Red Hat Enterprise Linux 6 | libpcap | Affected | n/a |
| Red Hat Enterprise Linux 7 | libpcap | Affected | n/a |
| Red Hat Enterprise Linux 8 | libpcap | Affected | n/a |
| Red Hat Enterprise Linux 9 | libpcap | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to libpcap 1.10.7.
Red Hat statement
This is an Important vulnerability in libpcap where a flaw in the BPF interpreter's register index validation can lead to out-of-bounds memory access. Exploitation requires a local attacker to provide a specially crafted BPF filter program to an application utilizing libpcap, which is considered an uncommon use case. This could result in arbitrary read and write operations within the OS process memory.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 8, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.11% (0.00108) | 1.09th | v5 (v2026.06.15) |
| Sep 6, 2026 | 0.11% (0.00107) | 1.23th | v5 (v2026.06.15) |
References (5)
- https://access.redhat.com/security/cve/CVE-2026-0799 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529093 Issue Tracking
- https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-0799
- https://www.cve.org/CVERecord?id=CVE-2026-0799
Change history (0)
No recorded changes yet.