Bug 2529899

Summary: CVE-2026-31912 libpcap: libpcap: Denial of service via crafted BPF filter program [fedora-all]
Product: [Fedora] Fedora Reporter: gkamathe
Component: libpcapAssignee: Michal Ruprich <mruprich>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: fhrdina, luhliari, mruprich, msekleta, thozza
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["19ae9a87-9d7d-4488-9a58-a3e759898640"]}
Fixed In Version: libpcap-1.10.7-1.fc44 libpcap-1.10.7-1.fc45 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-09-12 01:06:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2529088    

Description gkamathe 2026-09-08 15:54:48 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.

Comment 1 Fedora Update System 2026-09-10 09:01:54 UTC
FEDORA-2026-4401b94ad0 (libpcap-1.10.7-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-4401b94ad0

Comment 2 Fedora Update System 2026-09-10 09:02:15 UTC
FEDORA-2026-c3fb234b87 (libpcap-1.10.7-1.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-c3fb234b87

Comment 3 Fedora Update System 2026-09-11 01:35:00 UTC
FEDORA-2026-c3fb234b87 has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-c3fb234b87`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-c3fb234b87

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 4 Fedora Update System 2026-09-11 02:07:42 UTC
FEDORA-2026-4401b94ad0 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-4401b94ad0`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-4401b94ad0

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-09-11 02:27:44 UTC
FEDORA-2026-395bd81c94 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-395bd81c94`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-395bd81c94

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-12 01:06:34 UTC
FEDORA-2026-395bd81c94 (libpcap-1.10.7-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Fedora Update System 2026-09-13 00:16:59 UTC
FEDORA-2026-c3fb234b87 (libpcap-1.10.7-1.fc45) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.