CVE-2026-18313

Published: September 8, 2026Last modified: September 18, 2026

Description

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

Severity score breakdown

ParameterValue
Base score4.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Notes

we do not bundle rpcapd

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibpcapNot affected (1.10.1-r0)
25 LTSlibpcapNot affected (1.10.5-r0)
StreamlibpcapNot affected (1.10.1-r0)

References

ON THIS PAGE