PatchSiren cyber security CVE debrief
CVE-2016-7935 Tcpdump CVE debrief
CVE-2016-7935 is a critical memory-corruption issue in tcpdump’s RTP parser. According to NVD, tcpdump versions through 4.8.1 are affected, and the flaw is a buffer overflow in print-udp.c:rtp_print(). Because tcpdump processes network traffic, the issue is especially important anywhere packet capture or analysis is performed on untrusted input.
- Vendor
- Tcpdump
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Security teams, Linux distribution maintainers, and operators running tcpdump on untrusted network traffic should care most. This includes packet capture appliances, IDS/monitoring pipelines, and any system that uses tcpdump for live analysis or automated parsing.
Technical summary
The vulnerability is described as a buffer overflow in the RTP parsing path of tcpdump, specifically in print-udp.c:rtp_print(). NVD maps it to CWE-119 and assigns CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely reachable parsing flaw with severe confidentiality, integrity, and availability impact potential. The NVD CPE criteria mark tcpdump through 4.8.1 as vulnerable.
Defensive priority
High. Network-facing parsers are high-risk because they may be reached by crafted traffic during routine monitoring. The published severity is critical, and the affected version range covers releases prior to 4.9.0, so upgrade priority should be immediate for any exposed or actively used tcpdump deployment.
Recommended defensive actions
- Upgrade tcpdump to a version at or above 4.9.0.
- Inventory systems and appliances that ship or embed tcpdump, including distro packages and security tooling.
- Prioritize remediation on systems that process untrusted or externally sourced traffic.
- Apply vendor or distribution updates referenced in downstream advisories where direct package upgrades are not immediately possible.
- Confirm no stale 4.8.1-or-earlier packages remain in base images, golden images, or offline appliances.
Evidence notes
The CVE description states that the RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print(). NVD’s affected-version criteria specify tcpdump versions through 4.8.1. NVD also assigns CVSS 3.0 9.8 and CWE-119. Downstream advisories are referenced from Debian, Red Hat, and Gentoo, supporting that the issue was tracked by major vendors. No exploit details are included here beyond the supplied record.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7935 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7935
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7935 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7935
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.