VDB
CVE-2026-18313
CVE-2026-18313
PUBLISHED
CVSS 4.3 MEDIUM
Reported by Tcpdump · Published September 5, 2026
rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.
Risk Scores
CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| The Tcpdump Group | libpcap | 1.9.x, 1.10.x |
| The Tcpdump Group | libpcap | 1.9.x, 1.10.x, 1.9.x |
| The Tcpdump Group | libpcap |
Timeline
- Sep 5, 2026 Coalition ESS Score
- Sep 5, 2026 CVE Published
- Sep 6, 2026 EPSS Score
- Sep 8, 2026 CVE Updated
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score