PatchSiren cyber security CVE debrief
CVE-2016-7940 Tcpdump CVE debrief
CVE-2016-7940 is a critical memory-safety issue in tcpdump’s STP parser. According to NVD, tcpdump versions through 4.8.1 are affected, and the issue is described as a buffer overflow in print-stp.c affecting multiple functions. The CVSS vector is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high impact if malformed traffic or capture content is processed by a vulnerable build.
- Vendor
- Tcpdump
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Security teams, Linux distribution maintainers, and administrators who use tcpdump to inspect or process packet captures should prioritize this issue, especially where untrusted network data or shared capture files may be analyzed.
Technical summary
The vulnerable component is the STP parser in tcpdump’s print-stp.c. NVD classifies the weakness as CWE-119 and records a buffer overflow affecting multiple functions. The vulnerability applies to tcpdump versions up to and including 4.8.1; the description also states the issue is present before 4.9.0.
Defensive priority
Critical
Recommended defensive actions
- Upgrade tcpdump to 4.9.0 or later, as indicated by the version boundary in the advisory data.
- Confirm package versions on endpoints and in base images, especially on systems that analyze packet captures.
- Treat untrusted capture files and network traces as potentially dangerous inputs until patched versions are deployed.
- Use vendor or distribution advisories to verify backported fixes where a full version upgrade is not immediately available.
- Rebuild or redeploy any automation, appliances, or containers that bundle an affected tcpdump release.
Evidence notes
The CVE record and NVD entry identify tcpdump as the affected product and describe a buffer overflow in the STP parser within print-stp.c. NVD lists vulnerable versions through 4.8.1 inclusive and assigns CWE-119 with a CVSS 3.0 base score of 9.8. The NVD metadata also links vendor/distribution advisories from Debian, Red Hat, and Gentoo that can be used to verify remediation status.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7940 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7940
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7940 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7940
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.