pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument that deviates from the expected format, the function can read data beyond the end of the provided string and write data beyond the end of the allocated buffer.
Conclusion & alert: CVE-2025-11961 is rated Low Risk (8.1/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.10%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.01% | 0.10% | +0.09% |
| 2 | 2025-12-31 | — | 0.01% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.9 | 3.1 | LOW |
|
0.5 | 1.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
low | CVE-2025-11961: 1 source package rows (libpcap); 12 state rows across 6 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, 3.23-main, edge-main); fixed 0, open 12. | https://security.alpinelinux.org/vuln/CVE-2025-11961 |
debian
|
not yet assigned | CVE-2025-11961 not yet assigned priority: Debian including 1 source packages (libpcap), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2025-11961 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2025-11961 |
suse
|
low | CVE-2025-11961 severity low: SUSE including 266 source package names (13.2-9.1:gpg2-2.4.4-4.1, 13.2-9.1:pam-1.6.0-4.1, …), 475 product×package rows across 207 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (207 product lines)): Fixed 242, Known Affected 231, First Fixed 2. | https://www.suse.com/security/cve/CVE-2025-11961/ |
ubuntu
|
low | CVE-2025-11961 low priority: Ubuntu including 1 source packages (libpcap), 9 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): needs-triage 7, ignored 1, released 1. | https://ubuntu.com/security/CVE-2025-11961 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||