CVE-2026-18313: The Tcpdump Group Libpcap

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

Affected products

  • The Tcpdump Group Libpcap: from 1.9, before 1.10 (fixed in 1.10); from 1.10, before 1.10.7 (fixed in 1.10.7)

Published 2026-09-05. Last modified 2026-09-08.