Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes 11 vulnerabilities is now available.. openSUSE Security Update: Security update for tcpreplay ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0044-1 Rating: important References: #1218249 #1221324 #1222131 #1243845 #1247919 #1248322 #1248595 #1248596 #1248597 #1248964 #1250356 Cross-References: CVE-2023-4256 CVE-2023-43279 CVE-2024-22654 CVE-2024-3024 CVE-2025-51006 CVE-2025-8746 CVE-2025-9157 CVE-2025-9384 CVE-2025-9385 CVE-2025-9386 CVE-2025-9649 CVSS scores: CVE-2024-22654 (SUSE): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2025-8746 (SUSE): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 11 vulnerabilities is now available. Description: This update for tcpreplay fixes the following issues: - update to 4.5.2: * features added since 4.4.4 - fix/recalculate header checksum for ipv6-frag - IPv6 frag checksum support - AF_XDP socket support - tcpreplay -w (write into a pcap file) - tcpreaplay --fixhdrlen - --include and --exclude options - SLL2 support - Haiku support * security fixes reported for 4.4.4 fixed in 4.5.2 - CVE-2023-4256 / boo#1218249 - CVE-2023-43279 / boo#1221324 - CVE-2024-3024 / boo#1222131 (likely) - CVE-2024-22654 / boo#1243845 - CVE-2025-9157 / boo#1248322 - CVE-2025-9384 / boo#1248595 - CVE-2025-9385 / boo#1248596 - CVE-2025-9386 / boo#1248597 - CVE-2025-9649 / boo#1248964 - CVE-2025-51006 / boo#1250356 - seehttps://github.com/appneta/tcpreplay/compare/v4.4.4...v4.5.2 for full changelog - security fix for CVE-2025-8746 / boo#1247919 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-44=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): tcpreplay-4.5.2-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2023-4256.html https://www.suse.com/security/cve/CVE-2023-43279.html https://www.suse.com/security/cve/CVE-2024-22654.html https://www.suse.com/security/cve/CVE-2024-3024.html https://www.suse.com/security/cve/CVE-2025-51006.html https://www.suse.com/security/cve/CVE-2025-8746.html https://www.suse.com/security/cve/CVE-2025-9157.html https://www.suse.com/security/cve/CVE-2025-9384.html https://www.suse.com/security/cve/CVE-2025-9385.html https://www.suse.com/security/cve/CVE-2025-9386.html https://www.suse.com/security/cve/CVE-2025-9649.html https://bugzilla.suse.com/1218249 https://bugzilla.suse.com/1221324 https://bugzilla.suse.com/1222131 https://bugzilla.suse.com/1243845 https://bugzilla.suse.com/1247919 https://bugzilla.suse.com/1248322 https://bugzilla.suse.com/1248595 https://bugzilla.suse.com/1248596 https://bugzilla.suse.com/1248597 https://bugzilla.suse.com/1248964 https://bugzilla.suse.com/1250356 . Update available for tcpreplay fixing 11 vulnerabilities including important security issues affecting openSUSE.. tcpreplay update, openSUSE security, security fixes, important patch, network utility. . Severity: Important. LinuxSecurity.com Team
An update that fixes 11 vulnerabilities is now available.. openSUSE Security Update: Security update for tcpreplay ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0439-1 Rating: important References: #1218249 #1221324 #1222131 #1243845 #1247919 #1248322 #1248595 #1248596 #1248597 #1248964 #1250356 Cross-References: CVE-2023-4256 CVE-2023-43279 CVE-2024-22654 CVE-2024-3024 CVE-2025-51006 CVE-2025-8746 CVE-2025-9157 CVE-2025-9384 CVE-2025-9385 CVE-2025-9386 CVE-2025-9649 CVSS scores: CVE-2024-22654 (SUSE): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVE-2025-8746 (SUSE): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes 11 vulnerabilities is now available. Description: This update for tcpreplay fixes the following issues: - update to 4.5.2: * features added since 4.4.4 - fix/recalculate header checksum for ipv6-frag - IPv6 frag checksum support - AF_XDP socket support - tcpreplay -w (write into a pcap file) - tcpreaplay --fixhdrlen - --include and --exclude options - SLL2 support - Haiku support * security fixes reported for 4.4.4 fixed in 4.5.2 - CVE-2023-4256 / boo#1218249 - CVE-2023-43279 / boo#1221324 - CVE-2024-3024 / boo#1222131 (likely) - CVE-2024-22654 / boo#1243845 - CVE-2025-9157 / boo#1248322 - CVE-2025-9384 / boo#1248595 - CVE-2025-9385 / boo#1248596 - CVE-2025-9386 / boo#1248597 - CVE-2025-9649 / boo#1248964 - CVE-2025-51006 / boo#1250356 - security fix for CVE-2025-8746 / boo#1247919 PatchInstructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-439=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): tcpreplay-4.5.2-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2023-4256.html https://www.suse.com/security/cve/CVE-2023-43279.html https://www.suse.com/security/cve/CVE-2024-22654.html https://www.suse.com/security/cve/CVE-2024-3024.html https://www.suse.com/security/cve/CVE-2025-51006.html https://www.suse.com/security/cve/CVE-2025-8746.html https://www.suse.com/security/cve/CVE-2025-9157.html https://www.suse.com/security/cve/CVE-2025-9384.html https://www.suse.com/security/cve/CVE-2025-9385.html https://www.suse.com/security/cve/CVE-2025-9386.html https://www.suse.com/security/cve/CVE-2025-9649.html https://bugzilla.suse.com/1218249 https://bugzilla.suse.com/1221324 https://bugzilla.suse.com/1222131 https://bugzilla.suse.com/1243845 https://bugzilla.suse.com/1247919 https://bugzilla.suse.com/1248322 https://bugzilla.suse.com/1248595 https://bugzilla.suse.com/1248596 https://bugzilla.suse.com/1248597 https://bugzilla.suse.com/1248964 https://bugzilla.suse.com/1250356 . Critical security update for openSUSE tcpreplay fixing 11 issues. Installation instructions included for protection.. security update, openSUSE vulnerabilities, tcpreplay patch, important security fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # tcpreplay-4.5.1-2.1 on GA media Announcement ID: openSUSE-SU-2025:15570-1 Rating: moderate Cross-References: * CVE-2025-8746 CVSS scores: * CVE-2025-8746 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8746 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the tcpreplay-4.5.1-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tcpreplay 4.5.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8746.html . This notice highlights a notable security concern in tcpreplay for openSUSE Tumbleweed, delivering crucial update information.. tcpreplay security fix, openSUSE update, moderate vulnerabilities. . LinuxSecurity.com Team
Mostly bugfix release. More info here: https://github.com/appneta/tcpreplay/releases/tag/v4.5.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ecc001d6c5 2025-09-12 19:20:52.461593+00:00 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 43 Version : 4.5.2 Release : 1.fc43 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Mostly bugfix release. More info here: https://github.com/appneta/tcpreplay/releases/tag/v4.5.2 -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 29 2025 Bojan Smojver - 4.5.2-1 - Update to 4.5.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2388758 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2388758 [ 2 ] Bug #2388759 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2388759 [ 3 ] Bug #2388760 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2388760 [ 4 ] Bug #2388763 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388763 [ 5 ] Bug #2388764 - CVE-2025-9019 tcpreplay: tcpreplay Heap OverflowVulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388764 [ 6 ] Bug #2389866 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2389866 [ 7 ] Bug #2389867 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2389867 [ 8 ] Bug #2389868 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2389868 [ 9 ] Bug #2392223 - CVE-2025-9386 tcpreplay: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392223 [ 10 ] Bug #2392224 - CVE-2025-9386 tcpreplay: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392224 [ 11 ] Bug #2392225 - CVE-2025-9384 tcpreplay: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392225 [ 12 ] Bug #2392226 - CVE-2025-9384 tcpreplay: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2392226 [ 13 ] Bug #2392227 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392227 [ 14 ] Bug #2392228 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392228 [ 15 ] Bug #2392231 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2392231 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ecc001d6c5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Mostly bugfix release. More info here: https://github.com/appneta/tcpreplay/releases/tag/v4.5.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-16a1e1f512 2025-09-08 01:19:51.233951+00:00 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 41 Version : 4.5.2 Release : 1.fc41 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Mostly bugfix release. More info here: https://github.com/appneta/tcpreplay/releases/tag/v4.5.2 -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 29 2025 Bojan Smojver - 4.5.2-1 - Update to 4.5.2 * Fri Jul 25 2025 Fedora Release Engineering - 4.5.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Wed Jan 22 2025 Bojan Smojver - 4.5.1-5 - Drop unknown configure option --enable-tcpreplay-edit - Change tcpdump dependency to package - Remove checks for TX_RING support to avoid build problems * Sun Jan 19 2025 Fedora Release Engineering - 4.5.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Jul 29 2024 Miroslav Such - 4.5.1-3 - convert license to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2388758 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2388758 [ 2 ] Bug #2388759 - CVE-2025-9019 tcpreplay: tcpreplay HeapOverflow Vulnerability [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2388759 [ 3 ] Bug #2388760 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2388760 [ 4 ] Bug #2388763 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388763 [ 5 ] Bug #2388764 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388764 [ 6 ] Bug #2389866 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2389866 [ 7 ] Bug #2389867 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2389867 [ 8 ] Bug #2389868 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2389868 [ 9 ] Bug #2392223 - CVE-2025-9386 tcpreplay: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392223 [ 10 ] Bug #2392224 - CVE-2025-9386 tcpreplay: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392224 [ 11 ] Bug #2392225 - CVE-2025-9384 tcpreplay: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392225 [ 12 ] Bug #2392226 - CVE-2025-9384 tcpreplay: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2392226 [ 13 ] Bug #2392227 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392227 [ 14 ] Bug #2392228 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392228 [ 15 ] Bug #2392231 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2392231 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-16a1e1f512' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . The latest Tcpreplay release for Fedora 41 addresses significant heap overflow vulnerabilities. This upgrade is essential for improving both system security and performance.. tcpreplay Fedore 41 heap overflow fix. . Severity: Critical. LinuxSecurity.com Team
Mostly bugfix release. More info here: https://github.com/appneta/tcpreplay/releases/tag/v4.5.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9e9e727412 2025-09-08 00:54:32.786336+00:00 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 42 Version : 4.5.2 Release : 1.fc42 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Mostly bugfix release. More info here: https://github.com/appneta/tcpreplay/releases/tag/v4.5.2 -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 29 2025 Bojan Smojver - 4.5.2-1 - Update to 4.5.2 * Fri Jul 25 2025 Fedora Release Engineering - 4.5.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2388758 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2388758 [ 2 ] Bug #2388759 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2388759 [ 3 ] Bug #2388760 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2388760 [ 4 ] Bug #2388763 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388763 [ 5 ] Bug #2388764 - CVE-2025-9019 tcpreplay: tcpreplay Heap Overflow Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2388764 [ 6 ] Bug #2389866 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2389866 [ 7 ] Bug #2389867 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2389867 [ 8 ] Bug #2389868 - CVE-2025-9157 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2389868 [ 9 ] Bug #2392223 - CVE-2025-9386 tcpreplay: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392223 [ 10 ] Bug #2392224 - CVE-2025-9386 tcpreplay: appneta tcpreplay tcprewrite get.c get_l2len_protocol use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392224 [ 11 ] Bug #2392225 - CVE-2025-9384 tcpreplay: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392225 [ 12 ] Bug #2392226 - CVE-2025-9384 tcpreplay: appneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2392226 [ 13 ] Bug #2392227 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2392227 [ 14 ] Bug #2392228 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392228 [ 15 ] Bug #2392231 - CVE-2025-9385 tcpreplay: appneta tcpreplay tcprewriteedit_packet.c fix_ipv6_checksums use after free [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2392231 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9e9e727412' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Tcpreplay could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7231-1 January 28, 2025 tcpreplay vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Tcpreplay could be made to crash if it received specially crafted input. Software Description: - tcpreplay: Tool to replay saved tcpdump files at arbitrary speeds Details: It was discovered that Tcpreplay incorrectly handled memory when using the tcprewrite utility. A remote attacker could possibly use this issue to cause Tcpreplay to crash, resulting in a denial of service. (CVE-2023-27783) It was discovered that Tcpreplay incorrectly validated external input. A remote attacker could possibly use this issue to cause Tcpreplay to crash, resulting in a denial of service. (CVE-2023-27784, CVE-2023-27785, CVE-2023-27786, CVE-2023-27787, CVE-2023-27788, CVE-2023-27789) It was discovered that Tcpreplay incorrectly handled memory when using the tcprewrite utility. An attacker could possibly use this issue to cause Tcpreplay to crash, resulting in a denial of service. (CVE-2023-4256, CVE-2023-43279) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS tcpreplay 4.4.4-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS tcpreplay 4.3.4-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS tcpreplay 4.3.2-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS tcpreplay 4.2.6-1ubuntu0.1~esm5 Available with Ubuntu Pro Ubuntu 16.04 LTS tcpreplay 3.4.4-2+deb8u1ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7231-1 CVE-2023-27783, CVE-2023-27784, CVE-2023-27785, CVE-2023-27786, CVE-2023-27787, CVE-2023-27788, CVE-2023-27789, CVE-2023-4256, CVE-2023-43279 . Recent security updates for tcpreplay on Ubuntu focus on preventing crashes caused by crafted input vulnerabilities, enhancing stability and network security. tcpreplay security, Ubuntu updates, denial of service threat. . Severity: Critical. LinuxSecurity.com Team
Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-740d26aaf7 2024-07-21 02:14:42.426456 -------------------------------------------------------------------------------- Name : tcpreplay Product : Fedora 39 Version : 4.5.1 Release : 1.fc39 URL : http://tcpreplay.appneta.com/ Summary : Replay captured network traffic Description : Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep a tool to pre-process capture files to allow increased performance under certain conditions as well as capinfo which provides basic information about capture files. -------------------------------------------------------------------------------- Update Information: Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features: AF_XDP socket support - if you have a newer Linux kernel, you will be able to transmit at line rates without having to install 3rd party kernel modules (e.g. netmap, PF_RING) -w tcpreplay option - this overrides the -i option, and allows you to write to a PCAP file rather than an interface --include and --exclude tcpreplay options - allows replay of a list of specific packet numbers to replay. This may slow things down, so consider using in combination with -w. --fixhdrlen tcpreplay option - added to control action on packet length changes -W tcpreplay option - suppress warnings when replaying SLL2( Linux "cooked"capture encapsulation v2) Haiku support What's Changed Add support for LINUX_SLL2 by @btriller in #728 Feature #727 - Linux SLL v2 by @fklassen in #820 Bug #779 - honour overflow for all PPS values by @fklassen in #821 AF_XDP socket extension using libxdp api by @plangarbalint in #797 Feature #822 - AF_XDP socket extension by @fklassen in #823 Nanosec accurate packet processing by @plangarbalint in #796 Handle IPv6 fragment extension header by @ChuckCottrill in #832 Bug #837 - handle IPv6 fragment extension header by @fklassen in #838 Feature #796 - nanosecond packet processing by @fklassen in #836 configure.ac: unify search dirs for pcap and add lib32 by @shr-project in #819 Feature #839 - add pull request template by @fklassen in #840 ipv6 - add check for extension header length by @GabrielGanne in #842 Bug #827 PR #842 IPv6 extension header - staging by @fklassen in #859 add check for empty cidr by @GabrielGanne in #843 Bug #824 and PR #843: check for empty CIDR by @fklassen in #860 Add option to turn on/off fix packet header length by @ChuckCottrill in #846 Bug #703 #844 PR #846: optionally fix packet header length --fixhdrlen by @fklassen in #861 Bug 863: fix nansecond timestamp regression by @fklassen in #865 autotools - AC_HELP_STRING is obsolete in 2.70 by @GabrielGanne in #856 some Haiku support by @infrastation in #847 configure.ac: do not run conftest in case of cross compilation by @ChenQi1989 in #849 dlt_jnpr_ether_cleanup: check config before cleanup by @Marsman1996 in #851 Fix recursive tcpedit cleanup by @GabrielGanne in #855 Bug #813: back out PR #855 by @fklassen in #866 Bug #867 - run regfree() on close by @fklassen in #868 Bug #869 tcpprep memory leak include exclude by @fklassen in #870 Bug #811 - add check for invalid jnpr header length by @fklassen in #872 Bug #792 avoid assertion and other fixes by @fklassen in #873 Bug #844 tap: ignore TUNSETIFF EBUSY errors by @fklassen in #874 Bug #876 - add missing free_umem_and_xsk function by @fklassen in#877 Feature #878 - add -w / --suppress-warning option by @fklassen in #879 Bug #835 false unsupported dlt warnings on 802.3 (Ethernet I) and LLC by @fklassen in #880 Feature #884 include exclude options by @fklassen in #885 Feature #853 direct traffic to pcap by @fklassen in #871 Feature #853 restore missing -P command by @fklassen in #887 Bug #888: check for map == NULL in cidr.c by @fklassen in #889 -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 13 2024 Bojan Smojver - 4.5.1-1 - Update to 4.5.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-740d26aaf7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.