CVE-2025-9157: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free
A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untruncpacket of the file src/tcpedit/editpacket.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. This patch is called 73008f261f1cdf7a1087dc8759115242696d35da. Applying a patch is advised to resolve this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9157?
CVE-2025-9157 is classified as a high severity vulnerability due to its potential to cause a use after free condition.
How do I fix CVE-2025-9157?
To address CVE-2025-9157, it is recommended to update AppNeta tcpreplay and tcprewrite to versions beyond 4.5.2-beta2.
What are the affected versions of AppNeta tcpreplay related to CVE-2025-9157?
CVE-2025-9157 affects AppNeta tcpreplay versions up to and including 4.5.2-beta2.
What component is impacted by CVE-2025-9157?
CVE-2025-9157 impacts the untrunc_packet function found in src/tcpedit/edit_packet.c of the tcprewrite component.
How can CVE-2025-9157 be exploited?
CVE-2025-9157 can be exploited through manipulation, leading to a use after free condition during packet processing.