Off-by-one in Tcpreplay - #VU139349
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt heap memory and cause a denial of service.
The vulnerability exists due to an off-by-one heap-based buffer overflow in the ip_chaff fragroute module when processing an attacker-influenced fragroute rules file via tcprewrite's --fragroute feature. A remote attacker can supply a rules file containing an ip_chaff directive to corrupt heap memory and cause a denial of service.
Exploitation requires tcprewrite to be built with libdnet/fragroute support and operates on an ordinary IPv4 pcap without requiring crafted packet content.