Unrated severityOSV Advisory· Published Jan 29, 2026· Updated Feb 10, 2026
tcpflow has TIM Element OOB Write in wifipcap
CVE-2026-25061
Description
tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past tim.bitmap[251]. The overflow is small and DoS is the likely impact; code execution is potential, but still up in the air. The affected structure is stack-allocated in handle_beacon() and related handlers. As of time of publication, no known patches are available.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/simsong/tcpflow/security/advisories/GHSA-q5q6-frrv-9rj6mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.