CVE-2026-18313

Source
https://cve.org/CVERecord?id=CVE-2026-18313
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18313.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18313
Downstream
Published
2026-09-05T18:51:32.438Z
Modified
2026-09-06T03:45:49.001374956Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
rpcapd memory leak in libpcap before 1.10.7
Details

rpcapd can allocate up to 65536 bytes per each RPCAPMSGUPDATEFILTERREQ or RPCAPMSGSTARTCAPREQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

Database specific
{
    "cwe_ids": [
        "CWE-401"
    ],
    "cna_assigner": "Tcpdump",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.10.x"
                },
                {
                    "fixed": "1.10.7"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18313.json"
}
References

Affected packages

Git / github.com/the-tcpdump-group/libpcap

Affected ranges

Type
GIT
Repo
https://github.com/the-tcpdump-group/libpcap
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.9.x"
        },
        {
            "last_affected": "1.9.x"
        }
    ]
}

Affected versions

1.*
1.9.x
libpcap-1.*
libpcap-1.9-bp

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18313.json"