{"id":"openSUSE-SU-2026:22017-1","summary":"Security update for pcapplusplus","details":"This update for pcapplusplus fixes the following issues:\n\nChanges in pcapplusplus:\n\n- Update to version 26.07\n  * libpcap / WinPcap / Npcap is now optional.\n  * Bumped the minimum required C++ standard to C++14\n\n  Protocol support:\n\n  * Added Modbus protocol\n  * Added DoIP - Diagnostic over Internet Protocol\n  * Added PostgreSQL Wire Protocol (PGWire), including\n    additional message types\n  * Added MySQL Wire Protocol\n  * Discrete FTPControl and FTPData protocol types\n  * Add support for AccurateECN TCP flag\n  * Improve SIP packet detection using heuristic parsing\n  * Recognize LLC payload in SLL2\n\n  Added extensive X.509 / cryptography support:\n\n  * X.509 certificate decoding, extension parsing, and parsing\n    of X.509 certificates embedded in SSL/TLS messages\n  * Export/import of X.509 certificates to PEM format, plus a\n    new general-purpose PEM codec\n  * Cryptographic key decoders (RSA/EC private and public keys)\n  * Base64 encoding/decoding\n  * A new X509Toolkit example application\n  * Expanded ASN.1 codec support: BitString,\n    UTCTime/GeneralizedTime, ObjectIdentifier and string records,\n    plus arbitrary-size integer support\n  * IFileReaderDevice::createReader() and\n    IFileReaderDevice::tryCreateReader() use file-content\n    heuristics\n    to automatically pick the right reader (pcap/pcapng/snoop)\n    instead of relying solely on the file extension\n  * Add incremental packet parsing support with\n    Packet::parsePacket()\n  * Added multi-language README support: Japanese\n  * IPv4Address/IPv6Address/MacAddress user-defined literals,\n    e.g. constructing addresses directly from string literals,\n    and sized buffer-construction overloads\n  * Explicit-ownership overloads for RawPacket::setRawData(),\n    and a sized overload for Layer::copyData()\n  * Improved zstd support: added a build flag to control zstd\n    support\n  * A new SuppressLogs RAII class for temporarily suppressing\n    log output\n  * Large-scale internal refactoring of the device layer\n    (PcapLiveDevice, DpdkDeviceList, file readers/writers,\n    statistics tracking), the logging infrastructure, and the\n    packet parsing infrastructure, improving encapsulation,\n    thread-safety, and maintainability\n  * Improved benchmarking: added a pure-parsing benchmark and\n    extended benchmarks to support PcapNG and Snoop files\n  * Test refactoring: replace packet creation macros in with C++\n    functions\n  * Tons of security and correctness bug fixes\n\n  Breaking changes:\n\n  * The minimum required C++ standard has been raised to C++14\n  * IPcapDevice has been removed; its logic now lives in\n    PcapLiveDevice\n  * libpcap/WinPcap/Npcap is now an optional dependency -\n    building without it disables Pcap++ capture features, though\n    Common++/Packet++ (including pcap file I/O) remain fully\n    usable\n  * Various internal APIs around device lists and statistics\n    tracking were reworked as part of the refactoring above; this\n    may affect code relying on undocumented internals\n\n  Deprecation list:\n\n  * IPv6Address::copyTo() has been deprecated, please use\n    IPv6Address::copyToNewBuffer() instead\n  * MacAddress::copyTo() has been deprecated, please use\n    MacAddress::copyToNewBuffer() instead\n  * Asn1IntegerRecord::getValue() has been deprecated, please\n    use Asn1IntegerRecord::getIntValue() instead\n  * RawPacket::getObjectType() has been deprecated due to\n    unclear semantics\n  * RawPacket::setRawData() has been deprecated, please use the\n    overload that takes takeOwnership parameter for explicit\n    control\n  * RawPacket::initWithRawData() has been deprecated, please use\n    RawPacket::setRawData() with takeOwnership=false instead\n  * SSLExtension::SSLExtension() has been deprecated, please use\n    the constructor with bounded span instead\n  * Several TcpOptionBuilder constructors have been deprecated,\n    please use the new constructors with TcpOptionEnumType\n    instead\n  * TcpLayer::getTcpOption(TcpOptionType option) has been\n    deprecated, please use the overload\n    TcpLayer::getTcpOption(TcpOptionEnumType option) instead\n  * TcpLayer::removeTcpOption(TcpOptionType optionType) has been\n    deprecated, please use the overload\n    TcpLayer::removeTcpOption(TcpOptionEnumType optionType)\n    instead\n  * MBufRawPacket::getObjectType() has been deprecated due to\n    unclear semantics\n  * IFileReaderDevice::getReader() has been deprecated, please\n    use IFileReaderDevice::tryCreateReader() instead\n  * PcapFileReaderDevice::isNanoSecondPrecisionSupported() has\n    been deprecated, nanosecond precision is now natively\n    supported\n    by the internal parser and always returns true\n  * PcapFileWriterDevice::isNanoSecondPrecisionSupported() has\n    been deprecated, nanosecond precision is now natively\n    supported\n    by the internal parser and always returns true\n  * BpfFilterWrapper::matchPacketWithFilter() has been\n    deprecated, please use BpfFilterWrapper::matches() instead\n  * GeneralFilter::matchPacketWithFilter() has been deprecated,\n    please use GeneralFilter::matches() instead\n  * PcapLiveDevice::matchPacketWithFilter() has been deprecated,\n    please use GeneralFilter::matches() directly\n  * PcapLiveDevice::sendPacket(Packet* packet, bool checkMtu =\n    true) has been deprecated, please use\n    PcapLiveDevice::sendPacket(Packet const& packet, bool\n    checkMtu) instead\n  * PcapRemoteDeviceList::getRemoteDeviceByIP() has been\n    deprecated, please use PcapRemoteDeviceList::getDeviceByIP()\n    instead\n  * PfRingDeviceList::getPfRingDeviceByName() has been\n    deprecated, please use PfRingDeviceList::getDeviceByName()\n    instead\n\n- CVE-2026-13587: heap-based buffer overflow via function `parse_by_block_type` (boo#1269621)\n- CVE-2026-13588: heap-based buffer overflow via function `pcpp::SSLClientHelloMessage::getHandshakeVersion` (boo#1269620)\n- CVE-2026-13589: heap-based buffer overflow via function `pcpp::TelnetLayer::getSubCommand` (boo#1269619)\n- CVE-2026-13590: heap-based buffer overflow via function `pcpp::ModbusLayer::getLength` (boo#1269618)\n\n- Update to version 25.05\n\n  New protocol support:\n\n  * WireGuard\n  * Add gratuitous ARP requests\n  * GTPv2\n  * Cisco HDLC\n\n  New features:\n\n  * Added the option to build only Common++ and Packet++\n    libraries without Pcap++, removing the dependency on third-party\n    libraries like libpcap or WinPcap/Npcap\n  * Updated the CMake files to support using pcapplusplus/ as\n    the include prefix\n  * Added support for DPDK 23.11 and 24.11\n  * Introduced nanosecond precision for timestamps in TCP\n    reassembly\n  * Added support for timestamp-related libpcap options\n  * Added multi-language README support\n  * Introduced a new benchmark system using Google Benchmark\n  * Enhanced Python testing and linting infrastructure with ruff\n\n  Code refactoring:\n\n  * Overhauled the logging infrastructure for better performance\n    and flexibility\n  * Reformatted CMakeLists files using gersemi\n  * Updated the internal implementation of PcapLiveDevice to\n    store IP information as IPAddress\n  * Streamlined packet parsing using templated next-layer\n    sub-construction\n  * Refactored device list classes\n  * Improved the internal implementation of MacAddress,\n    IPAddress and IPNetwork classes\n  * Enhanced and modernized the internal implementation of\n    PfRingDevice\n  * Removed usage of VLAs\n  * Numerous C++11 modernization efforts\n  * Improved documentation using triple-slash Doxygen formatting\n\n  Other:\n\n  * Tons of bug fixes, security fixes and small improvements\n\n  Breaking changes:\n\n  * Logger::LogLevel has been deprecated and moved to LogLevel.\n    LogLevel is now an enum class, so arithmetic operations on it\n    will fail to compile\n  * The Logger copy constructor and copy assignment operator are\n    marked as deleted\n  * The return type of Packet::getRawPacketReadOnly() has been\n    changed from RawPacket* to RawPacket const*\n  * SSLv2 support has been removed\n\n  Deprecation list:\n\n  * PcapLiveDevice::getAddresses(), which was previously\n    deprecated, has now been removed\n  * libpcap versions \u003c 0.9 are no longer supported. As a result,\n    the following CMake options have been removed:\n    PCAPPP_ENABLE_PCAP_IMMEDIATE_MODE and\n    PCAPPP_ENABLE_PCAP_SET_DIRECTION\n  * The following methods are now deprecated and will be removed\n    in future versions:\n  * Logger::Error, Logger::Info, and Logger::Debug are\n    deprecated. Please use LogLevel::XXX instead\n  * PcapLiveDeviceList::getPcapLiveDeviceBy*** methods have been\n    deprecated in favor of PcapLiveDeviceList::getDeviceBy***\n  * ArpLayer(ArpOpcode opCode, const MacAddress &senderMacAddr,\n    const MacAddress &targetMacAddr, const IPv4Address\n    &senderIpAddr, const IPv4Address &targetIpAddr) constructor has\n    been deprecated in favor of more explicit overloads\n\n- version 24.09\n\n  New features:\n\n  * Added support for eBPF AF_XDP\n\n  New protocols:\n\n  * SMTP\n  * ASN.1 encoding and decoding\n  * Enabled ASN.1 root record parsing in x509 certificates\n  * LDAP\n  * S7COMM\n\n  DPDK improvements:\n\n  * DPDK 22.11 support\n  * Jumbo frames support\n  * Added an option to disable hugepages and driver verification\n    on initialization\n  * NUMA awareness\n\n  Examples and utils:\n\n  * Added XdpExample-FilterTraffic to demonstrate XdpDevice usage\n  * PcapSplitter: updated output filenames with 5-tuple\n    information\n  * Added support for nanosecond precision in reading and\n    writing pcap files\n  * Blocking mode packet capture now uses poll()\n  * Added millisecond precision timeout in RawSocketDevice\n  * Extended IPFilter to support IPv6 where possible\n  * Boosted build time with Ccache\n  * Fixed precision issue in pcapng file reader\n  * Improved method for retrieving the default gateway on macOS\n  * Added security and code of conduct guidelines\n  * Refactoring and modernization of the code base:\n  * Refactored and cleaned up live devices\n    + Added a getter for fetching all IP addresses as IPAddress\n    objects.\n  * Refactored IP address classes IPv4Address, IPv6Address,\n    IPAddress\n    + Added equality operators between IPAddress and in_addr\n      types\n  * Refactored the MAC address class MacAddress\n  * Ported PcapPlusPlus libraries to C++11\n  * Ported most of the examples and tutorials to C++11\n  * Refactored and cleaned up PF_RING devices\n  * Refactored and cleaned up the PointerVector class\n  * Converted Macro Guard to pragma once\n  * Replaced std::map with std::unordered_map\n  * Refactored large parts of the packet filtering code\n\n  Internal tools:\n\n  * Reformatted the entire code base using clang-format\n  * Added dependabot to keep GitHub Actions and Python packages\n    up-to-date\n  * Added OpenSSF Scorecard automation to monitor and enhance\n    security\n  * Transitioned from CirrusCI to GitHub Actions for all\n    workflows\n  * Scheduled regular CI builds\n  * Replaced deprecated netifaces by scapy\n  * Improved fuzzing coverage and added Fuzz CI\n  * Added a template for opening GitHub issues\n  * Upgraded LightPcapNg to the latest from master\n  * Fixed unhandled exceptions crashing the entire test suite\n\n  Other:\n\n  * Tons of bug fixes, security fixes and small improvements\n\n  Breaking changes:\n\n  * Removed isValid() from MacAddress, IPAddress, IPv4Address,\n    IPv6Address, instead they throw an exception if the input\n    argument is invalid\n  * Introduced a new TcpOptionEnumType\n  * Removed the dummy argument in PayloadLayer's constructor\n\n  Removed methods:\n\n  * IPv4Address::matchSubnet()\n\n  Methods now marked as deprecated:\n\n  * PointerVector::getAndRemoveFromVector() -\u003e replaced by\n    PointerVector::getAndDetach()\n  * HttpResponseLayer::HttpResponseLayer(version, statusCode,\n    statusCodeString) -\u003e use other constructors\n  * HttpResponseLayer::setStatusCode(newStatusCode,\n    statusCodeString) -\u003e use the other overload\n  * TcpOptionType enum -\u003e replaced by TcpOptionEnumType\n  * TcpOption::getTcpOptionType() -\u003e replaced by\n    TcpOption::getTcpOptionEnumType()\n  * TcpOptionBuilder::TcpOptionBuilder() -\u003e use other\n    constructors\n  * TcpLayer::getTcpOption(TcpOptionType option) -\u003e use the\n    other overload\n  * TcpLayer::addTcpOptionAfter() -\u003e replaced by\n    TcpLayer::insertTcpOptionAfter()\n  * TcpLayer::removeTcpOption() -\u003e use the other overload\n  * PcapLiveDevice::getAddresses() -\u003e replaced by\n    PcapLiveDevice::getIPAddresses()\n  * PcapRemoteDeviceList::getRemoteDeviceList() -\u003e replaced by\n    PcapRemoteDeviceList::createRemoteDeviceList()\n\n- version 23.09\n\n  New features:\n\n  * PcapPlusPlus moved from a custom build system to CMake!\n  * Added IP/IPv4/IPv6 network classes to better support netmask\n    and subnets\n  * Add support for opening NFLOG live device\n  * MAC address OUI Lookup\n  * Intel oneAPI compiler support\n\n  DPDK improvements:\n\n  * Properly support no RSS mode in DpdkDevice\n  * Make DPDK app name configurable\n  * More generic search of DPDK KNI kernel module in\n    setup_dpdk.py\n\n  New protocols:\n\n  * NFLOG\n  * SLL2\n  * TPKT\n  * COTP\n  * VRRP\n\n  Existing protocols improvements:\n\n  * HTTP - refactor and improve HttpResponseStatusCode\n  * SSL/TLS - better detection of possible encrypted handshake\n    messages\n  * DNS - support parsing of resources with larger data\n  * STP - add editing/crafting support\n  * ARP - add isRequest and isReply methods\n  * FTP-DATA support\n  * NTP - support Kiss of Death\n  * SIP - refactor status codes + add a few missing ones\n\n  New features:\n\n  * Modernize the codebase to use nullptr instead of NULL\n  * Remove usage of unsupported pcap_compile_nopcap()\n\n  Internal tools:\n\n  * Codecov integration for coverage reports\n  * Enable Clang-Tidy\n  * Enable cppcheck\n  * Improve the test framework\n  * Increase test coverage\n\n  Remove deprecated methods (due to typos):\n\n  * DhcpLayer::getMesageType() -\u003e replaced by\n    DhcpLayer::getMessageType()\n  * DhcpLayer::setMesageType() -\u003e replaced by\n    DhcpLayer::setMesasgeType()\n  * SSLHandshakeMessage::createHandhakeMessage() -\u003e replaced by\n    SSLHandshakeMessage::createHandshakeMessage()\n  * SSLClientHelloMessage::getExtensionsLenth() -\u003e replaced by\n    SSLClientHelloMessage::getExtensionsLength()\n  * SSLServerHelloMessage::getExtensionsLenth() -\u003e replaced by\n    SSLServerHelloMessage::getExtensionsLength()\n\n  Other:\n\n  * Tons of bug fixes, security fixes, major and minor\n    improvements\n","modified":"2026-10-03T17:23:11.032100828Z","published":"2026-10-01T13:13:37Z","related":["CVE-2026-13587","CVE-2026-13588","CVE-2026-13589","CVE-2026-13590"],"upstream":["CVE-2026-13587","CVE-2026-13588","CVE-2026-13589","CVE-2026-13590"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269618"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269620"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13587"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13589"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13590"}],"affected":[{"package":{"name":"pcapplusplus","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/pcapplusplus&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.07-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"pcapplusplus-devel":"26.07-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:22017-1.json"}}],"schema_version":"1.9.0"}