CVE-2020-8037
NixOS vulnerability analysis and mitigation

Overview

The vulnerability CVE-2020-8037 affects tcpdump version 4.9.3. The issue was discovered in the ppp decapsulator component, which can be convinced to allocate a large amount of memory. This vulnerability was disclosed in November 2020 (NVD).

Technical details

The vulnerability exists in the ppp decapsulator component of tcpdump where the buffer allocation doesn't properly account for captured data size. The buffer was being allocated based on the entire on-the-network packet size rather than just the captured portion, leading to excessive memory allocation. This was fixed by modifying the allocation to only account for the actual captured data size (GitHub Commit).

Impact

When exploited, this vulnerability can lead to a denial of service condition by causing the application to allocate excessive amounts of memory (Apple Security).

Exploitability

The vulnerability can be exploited remotely and requires no user interaction. An attacker can trigger the vulnerability by sending specially crafted network packets that the tcpdump ppp decapsulator would process (Ubuntu Security).

Mitigation and workarounds

The issue has been patched in various distributions and versions. Ubuntu has released fixes for versions 20.04 LTS (focal), 18.04 LTS (bionic), and 16.04 LTS (xenial). Fedora has released updates for versions 32 (tcpdump-4.9.3-4.fc32) and 33 (tcpdump-4.9.3-5.fc33). Apple has included fixes in Security Update 2021-002 Catalina (Fedora Update, Debian Update).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management