CVE-2026-18238: The Tcpdump Group Libpcap
Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
Affected products
- The Tcpdump Group Libpcap: from 1.8, before 1.9 (fixed in 1.9); from 1.9, before 1.10 (fixed in 1.10); from 1.10, before 1.10.7 (fixed in 1.10.7)
Published 2026-09-05. Last modified 2026-09-08.