CVE-2018-18408: Broadcom Tcpreplay
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.
Affected products
- Broadcom Tcpreplay: version 4.3.0 only
- Fedoraproject Fedora: version 28 only; version 29 only
Published 2018-10-17. Last modified 2026-06-17.