Bug 2397417 (CVE-2025-51006) - CVE-2025-51006 tcpreplay: double free in tcprewrite via a crafted pcap file
Summary: CVE-2025-51006 tcpreplay: double free in tcprewrite via a crafted pcap file
Keywords:
Status: NEW
Alias: CVE-2025-51006
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-22 14:01 UTC by OSIDB Bzimport
Modified: 2025-09-22 16:48 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-09-22 14:01:12 UTC
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binary, a local attacker can exploit this flaw to cause a Denial of Service (DoS) via memory corruption.


Note You need to log in before you can comment on or make changes to this bug.