AZL-99744
Dashboard / Vulnerabilities / AZL-99744
Summary: CVE-2026-0799 affecting package libpcap for versions less than 1.10.7-1
Details: In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-0799
Affected packages
Package
Name: libpcap
Purl: pkg:rpm/azure-linux/libpcap
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.10.7-1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
