CVE-2015-0261
Description
Integer signedness error in tcpdump's IPv6 mobility printer allows remote denial of service or potential code execution via a crafted negative length value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer signedness error in tcpdump's IPv6 mobility printer allows remote denial of service or potential code execution via a crafted negative length value.
Vulnerability
An integer signedness error exists in the mobility_opt_print function within the IPv6 mobility printer of tcpdump prior to version 4.7.2. When processing a malformed IPv6 mobility option, the function interprets a length field as a signed integer and passes a negative value to a memory operation, leading to an out-of-bounds read. This bug is reachable when tcpdump is used in live capture mode (without -w) or processes a crafted pcap file containing a malicious IPv6 packet. Affected versions include all tcpdump releases before 4.7.2 [1][2].
Exploitation
An attacker can trigger the vulnerability by sending a specially crafted IPv6 packet with a mobility header that contains a negative length value in the option field. No authentication is required; the attacker only needs to be able to inject packets onto a network segment where tcpdump is capturing traffic. The affected code path is reached when tcpdump decodes the mobility option, causing it to read beyond the buffer boundaries using the negative length as an index or size parameter [1][2].
Impact
Successful exploitation results in an out-of-bounds read that can cause tcpdump to crash, resulting in a denial of service. In some circumstances, the memory read may be leveraged by an attacker to execute arbitrary code on the system running tcpdump, potentially leading to a full compromise of the affected host [1]. The impact is rated Moderate by Red Hat, with a CVSS score not explicitly provided in the references but described as a medium-severity issue [2].
Mitigation
The vulnerability is fixed in tcpdump version 4.7.2 and later. Red Hat Enterprise Linux 7 users received an updated tcpdump package (4.9.0) as part of RHSA-2017:1871 [1]. Fedora distributions issued updates in March 2015 [3][4]. Users should upgrade to the latest version of tcpdump provided by their operating system vendor. No workarounds are documented; the only mitigation is to apply the patch or update the software.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
24- osv-coords22 versionspkg:rpm/opensuse/tcpdump&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/libpcap&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/tcpdump&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2
< 4.7.4-3.4+ 21 more
- (no CPE)range: < 4.7.4-3.4
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 1.8.1-9.1
- (no CPE)range: < 4.5.1-7.1
- (no CPE)range: < 4.9.0-13.1
- (no CPE)range: < 4.9.0-13.1
- (no CPE)range: < 4.5.1-7.1
- (no CPE)range: < 4.9.0-13.1
- (no CPE)range: < 4.9.0-13.1
- (no CPE)range: < 4.9.0-13.1
- (no CPE)range: < 4.5.1-7.1
- (no CPE)range: < 4.9.0-13.1
- (no CPE)range: < 4.9.0-13.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- advisories.mageia.org/MGASA-2015-0114.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-March/153834.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-March/153999.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-03/msg00084.htmlnvd
- packetstormsecurity.com/files/130730/tcpdump-Denial-Of-Service-Code-Execution.htmlnvd
- www.debian.org/security/2015/dsa-3193nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlnvd
- www.securityfocus.com/archive/1/534829/100/0/threadednvd
- www.securityfocus.com/bid/73019nvd
- www.securitytracker.com/id/1031937nvd
- www.ubuntu.com/usn/USN-2580-1nvd
- access.redhat.com/errata/RHSA-2017:1871nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.gentoo.org/glsa/201510-04nvd
News mentions
0No linked articles in our index yet.