Out-of-bounds read in Tcpreplay - #VU139398

 

Out-of-bounds read in Tcpreplay - #VU139398

Published: July 27, 2026


Vulnerability identifier: #VU139398
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in tcpreplay and tcpreplay-edit default non-LIBXDP send path when replaying a crafted pcap file with the --pktlen and --preload-pcap options. A remote attacker can supply a specially crafted pcap file to disclose sensitive information.

The issue occurs because the cached packet buffer is sized from the captured length while the transmitted length is taken from the packet header length field. No special build configuration is required.


Affected software

Tcpreplay

Remediation

Install security update from vendor's website.

Tcpreplay - update to 4.6.0 beta3

External References

Related Security Bulletins