ID:12844 - Exploit for Out-of-bounds write in Tcpreplay
Published: July 24, 2026
Vulnerability identifier: #VU139268
Vulnerability risk: Low
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Local access
Vulnerable software:
Tcpreplay
Tcpreplay
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in src/common/sendpacket.c within KHIAL interface. A local user can trigger an out-of-bounds write and gain access to senitive informatio on perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.