Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18238

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 5

Описание

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.

A flaw was found in libpcap. The rpcap client code, which processes RPCAP_MSG_PACKET messages from a server, incorrectly validates its headers. A malicious server could exploit this vulnerability by sending a specially crafted message, causing the client to read up to 20 bytes of memory beyond its intended buffer. This out-of-bounds read could lead to the disclosure of sensitive information from the client's process memory.

Отчет

This Moderate impact information disclosure flaw in libpcap's rpcap client allows a malicious server to read up to 20 bytes of client process memory. The vulnerability occurs when the client processes a crafted RPCAP_MSG_PACKET message, leading to an out-of-bounds read. Exploitation requires the client to connect to a controlled malicious server, limiting the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libpcapFix deferred
Red Hat Enterprise Linux 6libpcapFix deferred
Red Hat Enterprise Linux 7libpcapFix deferred
Red Hat Enterprise Linux 8libpcapFix deferred
Red Hat Enterprise Linux 9libpcapFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2529090libpcap: libpcap: Information disclosure via out-of-bounds read in rpcap client

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
16 дней назад

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.

CVSS3: 5
nvd
16 дней назад

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.

msrc
14 дней назад

OOBR in rpcap client in libpcap before 1.10.7

CVSS3: 5
debian
16 дней назад

The rpcap client code that processes a RPCAP_MSG_PACKET message receiv ...

CVSS3: 5
github
16 дней назад

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.

5 Medium

CVSS3

Уязвимость CVE-2026-18238