Out-of-bounds read in Tcpreplay - #VU142676
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in tcpprep/tcpreplay/tcprewrite cache-file parsing when processing a crafted cache file with a mismatched packets_per_byte value and index stride. A remote attacker can trick the victim into processing a crafted cache file to cause a denial of service and disclose sensitive information.
User interaction is required to run tcpprep, tcpreplay, or tcprewrite on an attacker-supplied cache file.