Out-of-bounds write in Tcpreplay - #VU139399
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and potentially execute arbitrary code.
The vulnerability exists due to out-of-bounds write in ARP-rewriting routines in src/tcpedit/edit_packet.c when processing an attacker-supplied pcap file with IP rewrite or randomization options enabled. A remote attacker can trick the victim into processing a crafted pcap file to cause a denial of service and potentially execute arbitrary code.
User interaction is required to process the crafted pcap file, and exploitation was confirmed via tcpreplay/tcpreplay-edit with --preload-pcap enabled.