VDB

CVE-2026-18313

CVE-2026-18313 PUBLISHED CVSS 4.3 MEDIUM

Reported by Tcpdump · Published September 5, 2026

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
The Tcpdump Grouplibpcap1.9.x, 1.10.x
The Tcpdump Grouplibpcap1.9.x, 1.10.x, 1.9.x
The Tcpdump Grouplibpcap

Timeline

  • Sep 5, 2026 Coalition ESS Score
  • Sep 5, 2026 CVE Published
  • Sep 6, 2026 EPSS Score
  • Sep 8, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

  • patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›