CVE-2026-18313: The Tcpdump Group Libpcap
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.
Affected products
- The Tcpdump Group Libpcap: from 1.9, before 1.10 (fixed in 1.10); from 1.10, before 1.10.7 (fixed in 1.10.7)
Published 2026-09-05. Last modified 2026-09-08.