CVE-2026-18313
rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.
- Published Sep 5, 2026
- CVSS 4.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available