PatchSiren cyber security CVE debrief
CVE-2016-7923 Tcpdump CVE debrief
CVE-2016-7923 is a critical memory-corruption flaw in tcpdump’s ARP parser. According to the CVE record, the issue is a buffer overflow in print-arp.c:arp_print() affecting tcpdump versions before 4.9.0. Because tcpdump is commonly used to inspect network traffic, systems that process untrusted packet data should treat this as a high-priority upgrade item.
- Vendor
- Tcpdump
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Anyone running tcpdump 4.8.1 or earlier, especially network administrators, SOC analysts, incident responders, and appliance or distro maintainers that ship tcpdump for packet inspection on untrusted traffic.
Technical summary
The supplied CVE and NVD data describe a buffer overflow in tcpdump’s ARP parsing path, specifically print-arp.c:arp_print(). NVD assigns CWE-119 and CVSS v3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable parsing flaw with severe potential impact if triggered while tcpdump processes crafted ARP data.
Defensive priority
Immediate / critical. Upgrade or replace affected tcpdump builds as soon as possible, and treat any instance processing untrusted packet captures or live network traffic as exposed until verified patched.
Recommended defensive actions
- Upgrade tcpdump to 4.9.0 or a vendor-patched package that explicitly fixes CVE-2016-7923.
- Check all servers, troubleshooting hosts, appliances, and security tooling for bundled tcpdump versions at or below 4.8.1.
- Apply the relevant vendor advisories from Debian, Red Hat, and Gentoo to ensure distro-specific backports are installed.
- Limit tcpdump usage on untrusted traffic to trusted operators and controlled systems until patching is complete.
Evidence notes
The core facts come from the supplied CVE description and NVD record: tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print(). NVD maps the issue to CWE-119 and rates it CVSS 3.0 9.8 with network reachability and high confidentiality, integrity, and availability impact. The supplied references also include Debian, Red Hat, and Gentoo advisories, supporting that multiple vendors issued remediation guidance. No KEV entry is present in the supplied enrichment, and the corpus does not include exploit code or upstream patch details.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7923 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7923
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7923 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7923
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.