Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
PCPP DNS Resource Decoding Crash
Summary
The PCPP library's DNS resource decoding feature may crash when processing certain DNS data. This could potentially allow an attacker to cause a program using PCPP to crash, but it's not clear how this would be exploited. To be safe, update to the latest version of PCPP.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| OSS-Fuzz | – | pcapplusplus | All versions |
Original title
Use-of-uninitialized-value in pcpp::IDnsResource::decodeName
Original description
OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=494047119
```
Crash type: Use-of-uninitialized-value
Crash state:
pcpp::IDnsResource::decodeName
pcpp::IDnsResource::IDnsResource
pcpp::DnsLayer::parseResources
```
```
Crash type: Use-of-uninitialized-value
Crash state:
pcpp::IDnsResource::decodeName
pcpp::IDnsResource::IDnsResource
pcpp::DnsLayer::parseResources
```
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=494047119 Third Party Advisory
Published: 20 Mar 2026 · Updated: 13 Jul 2026 · First seen: 13 Jul 2026