CVE-2025-9019: tcpreplay tcpprep cidr.c mask_cidr6 heap-based overflow
A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function maskcidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The researcher is able to reproduce this with the latest official release 4.5.1 and the current master branch. The code maintainer cannot reproduce this for 4.5.2-beta1. In his reply the maintainer explains that "[i]n that case, this is a duplicate that was fixed in 4.5.2."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9019?
CVE-2025-9019 is classified as a high severity vulnerability due to its potential for remote exploitation resulting in a heap-based buffer overflow.
How does CVE-2025-9019 exploit the affected software?
CVE-2025-9019 exploits the tcpreplay software by manipulating the function mask_cidr6 in the cidr.c file to cause a heap-based buffer overflow.
What versions of tcpreplay are affected by CVE-2025-9019?
CVE-2025-9019 affects tcpreplay version 4.5.1 and possibly earlier versions.
How do I fix CVE-2025-9019?
To fix CVE-2025-9019, update tcpreplay to a version that has patched this vulnerability.
Can CVE-2025-9019 be exploited remotely?
Yes, CVE-2025-9019 can be exploited remotely, making it critical to address the vulnerability promptly.