HomeDefectsLIN1022-17175
Not to be fixed

LIN1022-17175 : Security Advisory - tcpreplay - CVE-2025-9384

Created: Aug 24, 2025    Updated: Jan 26, 2026
Resolved Date: Jan 12, 2026
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 4.5.2-beta2 is recommended to address this issue. Upgrading the affected component is advised. The vendor explains, that he was "[a]ble to reproduce in 6fcbf03 but not in 4.5.2-beta2".

========Wind River Notice========

As per https://github.com/appneta/tcpreplay/issues/971, this issue was closed as "Cannot reproduce" without any substantial fixes.
As the vendor said, it cannot reproduce on 4.5.2-beta2.
We have tcpreplay 4.4.4 in this release. And we are not allowed to upgrade it to 4.5.* in this release as well.