CVE-2025-9019
NixOS vulnerability analysis and mitigation

Overview

A heap-based buffer overflow vulnerability has been discovered in tcpreplay version 4.5.1, specifically affecting the mask_cidr6 function in the cidr.c file of the tcpprep component. The vulnerability was identified in August 2025 and has been assigned CVE-2025-9019. The issue affects tcpreplay versions up to 4.5.1, with confirmation that it has been fixed in version 4.5.2-beta1 (NVD, GitHub Issue).

Technical details

The vulnerability occurs due to insufficient bounds checking in the IPv6 CIDR mask processing logic. The issue manifests when the mask_cidr6 function attempts to read beyond allocated memory boundaries while processing malformed IPv6 addresses. The vulnerability is triggered through the include option processing path via parse_xX_str at line 89. Specifically, when memory is allocated via our_safe_strdup in doOptInclude for a 2-byte string, the function attempts to read 1 byte beyond the allocated region. The vulnerability has been assigned a CVSS v3.1 base score of 3.1 (Low) with vector AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L (GitHub Issue).

Impact

The exploitation of this vulnerability can lead to heap-based buffer overflow, potentially causing memory corruption and program crashes. The attack can be initiated remotely, though the complexity of exploitation is considered high. While the vulnerability affects availability, there is no direct impact on confidentiality or integrity (VulDB).

Mitigation and workarounds

The vulnerability has been fixed in tcpreplay version 4.5.2-beta1. Users are advised to upgrade to this version or later to mitigate the vulnerability. The code maintainer has confirmed that the issue is resolved in the 4.5.2 release (GitHub Issue).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management