ID:12845 - Exploit for Out-of-bounds write in Tcpreplay
Published: July 24, 2026
Vulnerability identifier: #VU139272
Vulnerability risk: Low
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Local access
Vulnerable software:
Tcpreplay
Tcpreplay
Link to public exploit:
Vulnerability description
The vulnerability allows a local attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the ip6_opt fragroute module. A local attacker can trigger an out-of-bounds write and execute arbitrary code on the target system.
Remediation
Install updates from vendor's website.