PatchSiren cyber security CVE debrief
CVE-2017-5486 Tcpdump CVE debrief
CVE-2017-5486 is a critical buffer overflow in tcpdump’s ISO CLNS parser, specifically in print-isoclns.c:clnp_print(). NVD’s record marks affected tcpdump versions through 4.8.1 and assigns a CVSS 3.0 vector indicating network reachability, no privileges, no user interaction, and high confidentiality, integrity, and availability impact.
- Vendor
- Tcpdump
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Security teams running tcpdump on production hosts, packet capture appliances, analysis pipelines, and Linux distributions that package tcpdump 4.8.1 or earlier should prioritize this issue. It is especially relevant where tcpdump may process untrusted network traffic or packet captures.
Technical summary
The flaw is a buffer overflow in the ISO CLNS parsing path of tcpdump, with the vulnerable function identified as clnp_print() in print-isoclns.c. The CVE description places the issue in tcpdump before 4.9.0, while NVD’s CPE data marks tcpdump up to and including 4.8.1 as vulnerable and classifies the weakness as CWE-119.
Defensive priority
High. This is a critical memory-safety issue in a widely used packet analysis tool, with NVD assigning CVSS 9.8 and a network-based attack vector. Patch or replace affected builds promptly, especially on systems that analyze untrusted traffic or captures.
Recommended defensive actions
- Upgrade tcpdump to 4.9.0 or a vendor package that includes the fix.
- Inventory systems and images for tcpdump 4.8.1 and earlier, including embedded and offline analysis environments.
- Review distribution advisories and errata for package-specific remediation from Debian, Red Hat, and Gentoo.
- Limit tcpdump use on untrusted input until patched, and restrict who can run packet capture/analysis jobs.
- Validate that any backported security update in your distro actually includes the tcpdump fix rather than only a version string change.
Evidence notes
The CVE description states that the ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). NVD metadata supplies the affected CPE range (tcpdump through 4.8.1), CVSS 3.0 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and CWE-119 classification. The supplied references include Debian, Red Hat, and Gentoo advisories/errata, indicating ecosystem remediation activity. No KEV entry was supplied for this CVE.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5486 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5486
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5486 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5486
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.