Bug 2513846 (CVE-2026-33921)

Summary: CVE-2026-33921 Nozomi Networks Arc: Npcap Driver: Information disclosure and arbitrary packet sending via insecure access restrictions
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abrianik, ant, anujha, aschwart, asoldano, aszczucz, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, cmah, dandread, dhanak, dkreling, dlofthou, drichtar, drosa, dsimansk, eaguilar, ebaron, ewittman, fmongiar, ggrzybek, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jbuscemi, jmartisk, jmatsuok, jnethert, jpechane, jraez, jtolenti, kaycoth, kingland, lthon, manderse, mnovotny, mosmerov, mposolda, msvehla, nipatil, nwallace, olubyans, pantinor, parichar, pberan, pesilva, pgallagh, pjindal, pmackay, probinso, rguimara, rkubis, rmartinc, rruss, rstancel, rsvoboda, sausingh, sbiarozk, sdawley, ssilvert, sthorger, tasato, thjenkin, tqvarnst, vdosoudi, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Npcap driver. The Windows installer for Arc deployed Npcap with insecure default access restrictions, allowing any local user, not just administrators, to access the driver. This vulnerability enables a local user without administrative privileges to capture network traffic, leading to information disclosure from the host and other systems on the same network segment. Additionally, the user can send arbitrary raw packets on that segment.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-11 10:01:14 UTC
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment.