Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18313

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

A flaw was found in libpcap, specifically within the rpcapd daemon. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ messages. The rpcapd daemon allocates memory for these messages but fails to free it, leading to a memory leak. Over time, this can exhaust available memory, making the service unavailable.

Отчет

This Moderate impact memory leak in the rpcapd daemon, part of libpcap, can lead to a denial of service on Red Hat systems. A remote attacker with low privileges can send specially crafted RPCAP messages, causing rpcapd to continuously allocate memory without freeing it. This can exhaust system resources, rendering the service unavailable. The vulnerability is present when the rpcapd service is running and accessible over the network.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libpcapFix deferred
Red Hat Enterprise Linux 6libpcapFix deferred
Red Hat Enterprise Linux 7libpcapFix deferred
Red Hat Enterprise Linux 8libpcapFix deferred
Red Hat Enterprise Linux 9libpcapFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2529092libpcap: libpcap: Denial of Service via memory leak in rpcapd

EPSS

Процентиль: 12%
0.00212
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
16 дней назад

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

CVSS3: 4.3
nvd
16 дней назад

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

msrc
14 дней назад

rpcapd memory leak in libpcap before 1.10.7

CVSS3: 4.3
debian
16 дней назад

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_ ...

CVSS3: 4.3
github
16 дней назад

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

EPSS

Процентиль: 12%
0.00212
Низкий

4.3 Medium

CVSS3