Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binary, a local attacker can exploit this flaw to cause a Denial of Service (DoS) via memory corruption.

Subscriptions

Vendors Products
Appneta Subscribe
Tcpreplay Subscribe
Broadcom Subscribe
Tcpreplay Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30819 Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binary, a local attacker can exploit this flaw to cause a Denial of Service (DoS) via memory corruption.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom tcpreplay
CPEs cpe:2.3:a:broadcom:tcpreplay:4.5.1:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom tcpreplay

Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Appneta
Appneta tcpreplay
Vendors & Products Appneta
Appneta tcpreplay

Mon, 22 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binary, a local attacker can exploit this flaw to cause a Denial of Service (DoS) via memory corruption.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-09-22T15:53:57.492Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51006

cve-icon Vulnrichment

Updated: 2025-09-22T15:53:26.511Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-22T14:15:49.713

Modified: 2025-10-14T19:58:01.560

Link: CVE-2025-51006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-23T16:09:55Z

Weaknesses