CVE-2025-11964: The Tcpdump Group Libpcap
Low severity, CVSS 1.9. EPSS: 0.1% chance of exploitation in the next 30 days.
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.
Affected products
- The Tcpdump Group Libpcap: from 1.10.0, before 1.10.6 (fixed in 1.10.6)
Published 2025-12-31. Last modified 2026-06-17.