Out-of-bounds write in Tcpreplay - #VU139348

 

Out-of-bounds write in Tcpreplay - #VU139348

Published: July 24, 2026


Vulnerability identifier: #VU139348
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in the tcprewrite fragroute rules parser in mod_open() when parsing a supplied fragroute rules file. A remote attacker can supply a specially crafted rules file to execute arbitrary code.

User interaction is required to open or process the crafted rules file, and the issue is triggered during startup before any packet is processed. Only builds with fragroute support enabled are vulnerable.


Affected software

Tcpreplay

Remediation

Install security update from vendor's website.

Tcpreplay - addressed in versions 4.5.5, 4.6.0 beta2

External References

Related Security Bulletins