Off-by-one in Tcpreplay - #VU139349

 

Off-by-one in Tcpreplay - #VU139349

Published: July 24, 2026


Vulnerability identifier: #VU139349
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-193
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to corrupt heap memory and cause a denial of service.

The vulnerability exists due to an off-by-one heap-based buffer overflow in the ip_chaff fragroute module when processing an attacker-influenced fragroute rules file via tcprewrite's --fragroute feature. A remote attacker can supply a rules file containing an ip_chaff directive to corrupt heap memory and cause a denial of service.

Exploitation requires tcprewrite to be built with libdnet/fragroute support and operates on an ordinary IPv4 pcap without requiring crafted packet content.


Affected software

Tcpreplay

Remediation

Install security update from vendor's website.

Tcpreplay - addressed in versions 4.5.5, 4.6.0 beta2

External References

Related Security Bulletins