Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN873
_____________________________________________________________________

DATE                : 09/09/2026

HARDWARE PLATFORM(S): / 

OPERATING SYSTEM(S): Systems running libpcap versions prior to 1.10.7.
 
=====================================================================
https://seclists.org/tcpdump/2026/q3/14
_____________________________________________________________________

Hello all.

libpcap 1.10.7 has been published yesterday, its main focus is fixing of
the following vulnerabilities:

* CVE-2026-0799 (reported by Include Security in 2018, sponsored by
  Mozilla under the Secure Open Source program, but reproduced only in
  2026)
* CVE-2026-31912
* CVE-2026-31911 (reported by FuzzAnything Organization)
* CVE-2026-6244
* CVE-2026-6554 (reported by Kaixuan LI)
* CVE-2026-18313
* CVE-2026-18238

All users are advised to update.  For the CVE-2026-31912 fix to have
effect, application that use the now deprecated bpf_filter() must be
migrated to pcap_offline_filter().

Also this release makes it clear that the remote packet capture code is
still an experimental work in progress and is not yet safe enough for
production or non-trusted environments.

-- 
    Denis Ovsienko


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




