Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

PCPP DNS Resource Decoding Crash

Summary

The PCPP library's DNS resource decoding feature may crash when processing certain DNS data. This could potentially allow an attacker to cause a program using PCPP to crash, but it's not clear how this would be exploited. To be safe, update to the latest version of PCPP.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
Ecosystem VendorProductAffected versions
OSS-Fuzz – pcapplusplus All versions
Original title
Use-of-uninitialized-value in pcpp::IDnsResource::decodeName
Original description
OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=494047119

```
Crash type: Use-of-uninitialized-value
Crash state:
pcpp::IDnsResource::decodeName
pcpp::IDnsResource::IDnsResource
pcpp::DnsLayer::parseResources
```
Published: 20 Mar 2026 · Updated: 13 Jul 2026 · First seen: 13 Jul 2026