Back

MEDIUM

infinte loop in libpcap before 1.10.7

Published Sep 5, 2026

Description

libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.

Affected products

Remediation

Vendor solution

Upgrade to libpcap 1.10.7.

Red Hat statement

This Moderate impact flaw in libpcap's BPF interpreter could lead to a denial of service. Exploitation requires a local attacker with low privileges to provide a specially crafted filter program, causing an infinite loop and resource exhaustion. This limits the attack surface to specific, uncommon use cases where arbitrary BPF filters can be supplied.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Tcpdump
Published Sep 5, 2026
Updated Sep 8, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Awaiting Analysis
Modified Sep 8, 2026
Red Hat
Severity Moderate
Public date Sep 5, 2026