In tcpdump 4.10.0-PRE-GIT, the SOME/IP dissector used the tok2strbuf() function in an unsafe manner. This could potentially lead to undefined behavior, such as buffer overflows or memory corruption, depending on how the function is misused within the dissector.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is not a standalone weaponized exploit; it is a reproducible vulnerability environment for CVE-2020-8036 in tcpdump. The core purpose is to provide the vulnerable tcpdump source tree, a deterministic build script, build logs, and an ASan/UBSan-instrumented binary so a researcher can craft a malformed SOME/IP packet capture and trigger the bug reliably. Exploit capability: the practical capability is denial-of-service / crash reproduction via malformed input. The vulnerability is an out-of-bounds read (CWE-125) in tcpdump’s SOME/IP dissector, described as unsafe use of tok2strbuf() in print-someip.c. There is no included malicious payload, shell, persistence, or post-exploitation logic. Successful use yields a sanitizer-detected crash and stack trace, not code execution. Repository structure: top-level documentation includes README.md, description.md, and meta.json describing the CVE, vulnerable file, commit metadata, and reproduction goal. The compile/ directory contains build.sh, deps.txt, BUILD_OK, build.log, binary_size.txt, and artifacts. BUILD_OK confirms the main binary is /compile/artifacts/tcpdump with /compile/artifacts/main as a symlink entry point. The src/tcpdump/ directory contains the full vulnerable upstream tcpdump source tree at the vulnerable commit, including autotools/CMake build files, CI configs, protocol dissectors, compatibility code, and documentation. Build/repro details: compile/build.sh installs clang-10, libpcap0.8-dev, bison, flex, m4, and pkg-config; sets CFLAGS/LDFLAGS to -fsanitize=address,undefined; runs ./configure and make; and copies the resulting tcpdump binary into compile/artifacts/. The environment is Ubuntu 20.04-based and intended for local reproduction. The README explicitly states that constructing a pcap that reaches the SOME/IP parsing path should trigger the ASan report. Attack surface: primarily file-based, because the intended trigger is a crafted pcap read by tcpdump. Secondarily, the vulnerable code is a network protocol dissector, so equivalent malformed live traffic could also reach the same parser if tcpdump captures it. No hardcoded victim IPs, C2, or exploit delivery infrastructure are present. Notable endpoint observations: most extracted endpoints are project/build related rather than exploit targets. They include local artifact paths (/src/tcpdump/, /compile/artifacts/tcpdump), upstream repository URLs, and CI/dependency URLs. No attacker-controlled remote infrastructure is embedded in the repo.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.