cbcvebase.
CVE-2025-11964
published 2025-12-31

CVE-2025-11964: On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes…

PriorityP48low1.9CVSS 3.1
AVLACHPRHUINSUCNILAN
EPSS
0.10%
1.1th percentile
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlibpcap
linuxlinux_kernel>= 4.17.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
msrcazl3_libpcap_1.10.5-1_on_azure_linux_3.0
msrcazl3_nmap_7.95-2_on_azure_linux_3.0
msrccbl2_libpcap_1.10.1-4_on_cbl_mariner_2.0
msrccbl2_nmap_7.93-3_on_cbl_mariner_2.0
the_tcpdump_grouplibpcap>= 1.10.0 < 1.10.61.10.6

CVSS provenance

nvdv3.11.9LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_debian1.9LOW
vendor_msrc1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.