Out-of-bounds write in Tcpreplay - #VU139350
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to out-of-bounds write in tcprewrite fragroute tcp_seg and ip_frag modules when parsing a negative size value from an attacker-influenced fragroute rules file. A remote attacker can supply a specially crafted rules file to execute arbitrary code or cause a denial of service.
Exploitation requires tcprewrite to be built with libdnet fragroute support and invoked with the --fragroute option. No crafted packet content is required.