Infinite Loop Vulnerability in libpcap BPF Interpreter by tcpdump
CVE-2026-6554
5.5MEDIUM
Key Information:
- Vendor
The Tcpdump Group
- Status
- Vendor
- CVE Published:
- 5 September 2026
Badges
👾 Exploit Exists
What is CVE-2026-6554?
The libpcap library's BPF interpreter has a vulnerability that allows crafted filter programs to exploit the handling of offsets in 'ja L' instructions, causing infinite looping. This occurs due to the failure to restrict the number of iterations during backward jumps in certain uncommon use cases. As a result, an attacker could create a filter that leads to execution indefinitely, potentially causing a denial of service scenario.
Affected Version(s)
libpcap 0 < 1.10.7
