CVE-2025-51006: Double Free
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dltlinuxsll2cleanup() function in plugins/dltlinuxsll2/linuxsll2.c. This vulnerability is triggered when tcpeditdltcleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binary, a local attacker can exploit this flaw to cause a Denial of Service (DoS) via memory corruption.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51006?
CVE-2025-51006 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-51006?
To fix CVE-2025-51006, update your tcpreplay software to the latest version that addresses this vulnerability.
What are the impacts of CVE-2025-51006?
The impact of CVE-2025-51006 includes potential application crashes and the ability for an attacker to execute arbitrary code.
Which versions of tcpreplay are affected by CVE-2025-51006?
CVE-2025-51006 affects all versions of tcpreplay prior to the patch release that addresses this vulnerability.
Is CVE-2025-51006 a common vulnerability?
CVE-2025-51006 is recognized as a serious and relatively common vulnerability in the tcpreplay package, highlighting the importance of secure coding practices.