Memory Validation Flaw in libpcap Client Exposes User Data Risk
CVE-2026-18238

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-18238?

A flaw in the rpcap client of libpcap occurs due to improper validation of headers in the RPCAP_MSG_PACKET messages received from servers. This vulnerability allows a malicious server to craft a message that tricks the client into interpreting up to 20 bytes of memory beyond the buffer's end as legitimate packet data. This can lead to unauthorized access and exposure of sensitive process memory, posing significant risks to user data integrity and privacy.

Affected Version(s)

libpcap 1.8.x

libpcap 1.9.x

libpcap 1.10.x < 1.10.7

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.