CVE-2025-11961
published 2025-12-31CVE-2025-11961: pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a…
PriorityP49low1.9CVSS 3.1
AVLACHPRHUINSUCNILAN
EPSS
0.10%
0.9th percentile
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpcap | < libpcap 1.10.6-1 (forky) | libpcap 1.10.6-1 (forky) |
| msrc | azl3_libpcap_1.10.5-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_nmap_7.95-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_nmap_7.95-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libpcap_1.10.1-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libpcap_1.10.1-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nmap_7.93-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nmap_7.93-4_on_cbl_mariner_2.0 | — | — |
| tcpdump | libpcap | >= 0 < 1.10.6-1 | 1.10.6-1 |
| the_tcpdump_group | libpcap | < 1.10.6 | 1.10.6 |
CVSS provenance
nvdv3.11.9LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_msrc1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libpcap: libpcap: Memory corruption via malformed MAC-48 address input
vendor_redhat·2025-12-31·CVSS 1.9
CVE-2025-11961 [LOW] CWE-787 libpcap: libpcap: Memory corruption via malformed MAC-48 address input
libpcap: libpcap: Memory corruption via malformed MAC-48 address input
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
A flaw was found in libpcap. The pcap_ether_aton() function, which processes MAC-48 addresses, does not properly validate input strings. An application that calls this function with a malformed address string can cause the function to read or write
Microsoft
OOBR and OOBW in pcap_ether_aton() in libpcap
vendor_msrc·2025-12-09·CVSS 1.9
CVE-2025-11961 [LOW] CWE-126 OOBR and OOBW in pcap_ether_aton() in libpcap
OOBR and OOBW in pcap_ether_aton() in libpcap
Mariner: Mariner
Tcpdump: Tcpdump
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-11961: libpcap - pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argumen...
vendor_debian·2025·CVSS 1.9
CVE-2025-11961 [LOW] CVE-2025-11961: libpcap - pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argumen...
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.10.6-1)
sid: resolved (fixed in 1.10.6-1)
trixie: open
OSV
CVE-2025-11961: pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer
osv·2025-12-31·CVSS 1.9
CVE-2025-11961 [LOW] CVE-2025-11961: pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
GHSA
GHSA-x25x-vjrm-h7qq: pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer
ghsa_unreviewed·2025-12-31
CVE-2025-11961 [LOW] CWE-122 GHSA-x25x-vjrm-h7qq: pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-11961 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-11961 [HIGH] CVE-2025-11961 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11961 :
Nmap vulnerability analysis and mitigation
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
Source : NVD
## 1.9
Score
Published December 31, 2025
Severity LOW
CNA Score 1.9
Affected Technologies
Nmap
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Bugzilla
CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input
bugzilla·2025-12-31·CVSS 1.9
CVE-2025-11961 [LOW] CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input
CVE-2025-11961 libpcap: libpcap: Memory corruption via malformed MAC-48 address input
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
2025-12-31
Published