CVE-2026-18313

MEDIUM
4.3CVSS v3
CVSS v2
0.21% EPSS (exploit probability)
CWE-401CWE

Description

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references