Off-by-one in Tcpreplay - #VU139347
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an off-by-one heap-based buffer overflow in the tcp_chaff fragroute module when processing an attacker-influenced fragroute rules file with a tcp_chaff directive. A remote user can supply a crafted rules file to cause a denial of service.
Exploitation requires tcprewrite to be built with libdnet/fragroute support and invoked with the --fragroute option against a pcap containing TCP traffic with payload data and the ACK flag set.