Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31912

Опубликовано: 05 сент. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.

A flaw was found in libpcap. The BPF interpreter in libpcap does not correctly handle crafted filter programs, leading to an out-of-bounds read. A local attacker could provide a specially crafted filter program, causing the interpreter to attempt to read memory outside of its allocated buffer. This could result in a denial of service due to an application crash.

Отчет

Moderate: A flaw in the libpcap BPF interpreter allows a local attacker to trigger an out-of-bounds read by supplying a specially crafted BPF filter program. This can lead to a denial of service or information disclosure in uncommon use cases where applications process untrusted BPF filters. The impact is limited by the requirement for local access and specific application configurations.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libpcapFix deferred
Red Hat Enterprise Linux 6libpcapFix deferred
Red Hat Enterprise Linux 7libpcapFix deferred
Red Hat Enterprise Linux 8libpcapFix deferred
Red Hat Enterprise Linux 9libpcapFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2529088libpcap: libpcap: Denial of service via crafted BPF filter program

EPSS

Процентиль: 1%
0.00098
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
8 дней назад

(libpcap BPF interpreter detects neither reaching the end of the filter ...)

CVSS3: 5.5
nvd
9 дней назад

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.

msrc
8 дней назад

OOBR in libpcap before 1.10.7

CVSS3: 5.5
debian
9 дней назад

libpcap BPF interpreter detects neither reaching the end of the filter ...

CVSS3: 5.5
github
9 дней назад

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.

EPSS

Процентиль: 1%
0.00098
Низкий

6.1 Medium

CVSS3