Out-of-bounds write in Tcpreplay - #VU139348
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in the tcprewrite fragroute rules parser in mod_open() when parsing a supplied fragroute rules file. A remote attacker can supply a specially crafted rules file to execute arbitrary code.
User interaction is required to open or process the crafted rules file, and the issue is triggered during startup before any packet is processed. Only builds with fragroute support enabled are vulnerable.