CVE-2020-8037
NixOS vulnerability analysis and mitigation

Overview

The vulnerability CVE-2020-8037 affects tcpdump version 4.9.3. The issue was discovered in the ppp decapsulator component, which can be convinced to allocate a large amount of memory. This vulnerability was disclosed in November 2020 (NVD).

Technical details

The vulnerability exists in the ppp decapsulator component of tcpdump where the buffer allocation doesn't properly account for captured data size. The buffer was being allocated based on the entire on-the-network packet size rather than just the captured portion, leading to excessive memory allocation. This was fixed by modifying the allocation to only account for the actual captured data size (GitHub Commit).

Impact

When exploited, this vulnerability can lead to a denial of service condition by causing the application to allocate excessive amounts of memory (Apple Security).

Mitigation and workarounds

The issue has been patched in various distributions and versions. Ubuntu has released fixes for versions 20.04 LTS (focal), 18.04 LTS (bionic), and 16.04 LTS (xenial). Fedora has released updates for versions 32 (tcpdump-4.9.3-4.fc32) and 33 (tcpdump-4.9.3-5.fc33). Apple has included fixes in Security Update 2021-002 Catalina (Fedora Update, Debian Update).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-32322HIGH7.8
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-26439HIGH7.8
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-26431HIGH7.8
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-22415MEDIUM4
  • NixOSNixOS
  • android
NoNoSep 04, 2025
CVE-2025-26419LOW3.3
  • NixOSNixOS
  • android
NoNoSep 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management