CVE-2025-11964: The Tcpdump Group Libpcap

Low severity, CVSS 1.9. EPSS: 0.1% chance of exploitation in the next 30 days.

On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.

Affected products

Published 2025-12-31. Last modified 2026-06-17.