libpcap 的 BPF 解释器将 'ja L' BPF 指令中的偏移量视为有符号整数,以实现通过向后跳转构成的循环,但没有限制循环迭代次数。在某些不常见的使用场景中,一个精心构造的过滤程序可能导致解释器陷入无限循环。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The Tcpdump Group | libpcap | < 1.10.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Tcpdump Group | libpcap | 0 ~ 1.10.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-0799 | 8.7 HIGH | OOBR and OOBW in libpcap before 1.10.7 |
| CVE-2026-6244 | 5.5 MEDIUM | division by zero in libpcap before 1.10.7 |
| CVE-2026-31911 | 5.5 MEDIUM | abort() in libpcap before 1.10.7 on an invalid BPF opcode |
| CVE-2026-31912 | 5.5 MEDIUM | OOBR in libpcap before 1.10.7 |
| CVE-2026-18238 | 5.0 MEDIUM | OOBR in rpcap client in libpcap before 1.10.7 |
| CVE-2026-18313 | 4.3 MEDIUM | rpcapd memory leak in libpcap before 1.10.7 |
No comments yet