PatchSiren cyber security CVE debrief
CVE-2016-7930 Tcpdump CVE debrief
CVE-2016-7930 is a critical memory-safety issue in tcpdump’s LLC/SNAP parser. The flaw is in print-llc.c:llc_print() and can lead to a buffer overflow when tcpdump processes crafted input. NVD rates the issue 9.8/10 and lists affected tcpdump versions through 4.8.1, with tcpdump 4.9.0 as the fixed release target referenced by the vulnerability description.
- Vendor
- Tcpdump
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Administrators, incident responders, and security teams that run tcpdump on untrusted packet captures or live traffic should treat this as high priority, especially on systems where tcpdump is used routinely for troubleshooting or automated analysis.
Technical summary
NVD describes the weakness as a buffer overflow in tcpdump’s LLC/SNAP parsing path, specifically print-llc.c:llc_print(), mapped to CWE-119. The CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a network-reachable issue with no privileges or user interaction required and potential high impact to confidentiality, integrity, and availability. NVD’s affected CPE range includes tcpdump versions up to 4.8.1.
Defensive priority
Urgent. This is a critical, unauthenticated, network-reachable parser bug in a widely used analysis tool, so systems exposing tcpdump to untrusted traffic or captures should be prioritized for upgrade and exposure reduction.
Recommended defensive actions
- Upgrade tcpdump to 4.9.0 or later, or to a vendor package that explicitly includes the fix.
- Check systems and images for tcpdump versions at or below 4.8.1, using package inventory or software composition tools.
- Limit tcpdump use on untrusted captures and live traffic to trusted, controlled workflows until patched.
- Review vendor advisories referenced in the CVE record, including Debian DSA-3775, Red Hat RHSA-2017:1871, and Gentoo GLSA-201702-30, for distro-specific remediation guidance.
- If immediate upgrading is not possible, reduce exposure by removing unnecessary tcpdump installations and restricting who can run packet-analysis jobs on sensitive systems.
Evidence notes
The debrief is based on the NVD CVE record and the CVE description supplied in the source corpus. NVD lists the issue as a CWE-119 buffer overflow with CVSS 9.8 and affected tcpdump versions through 4.8.1. Supporting vendor and third-party references in the record include Debian DSA-3775, Red Hat RHSA-2017:1871, Gentoo GLSA-201702-30, SecurityFocus BID 95852, and SecurityTracker 1037755.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7930 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7930
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7930 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7930
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.