Back

HIGH

OOBR and OOBW in libpcap before 1.10.7

Published Sep 5, 2026

Description

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Affected products

Remediation

Vendor solution

Upgrade to libpcap 1.10.7.

Red Hat statement

This is an Important vulnerability in libpcap where a flaw in the BPF interpreter's register index validation can lead to out-of-bounds memory access. Exploitation requires a local attacker to provide a specially crafted BPF filter program to an application utilizing libpcap, which is considered an uncommon use case. This could result in arbitrary read and write operations within the OS process memory.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Tcpdump
Published Sep 5, 2026
Updated Sep 8, 2026
Reserved Jan 8, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Awaiting Analysis
Modified Sep 8, 2026
Red Hat
Severity Important
Public date Sep 5, 2026