The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1760626]
While printing a REPLAY-STATUS notify message used in IKEv1, function ikev1_n_print() in print-isakmp.c can read beyond the limits of the captured buffer, if there are not enough bytes in the buffer to read the 32bits value that indicates whether the replay detection is enabled or not. This may print memory data on the victim's screen or crash the tcpdump application.