CVE-2026-8275

NameCVE-2026-8275
DescriptionA vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBody of the file modules/zerogod/zerogod_ipp_primitives.go of the component zerogod IPP Service. Performing a manipulation results in integer coercion error. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is named 3731d5576cffae9eefe3721cd46a40933304129f. To fix this issue, it is recommended to deploy a patch.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1136448

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bettercap (PTS)bookworm2.32.0-1vulnerable
trixie2.33.0-1vulnerable
forky, sid2.33.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bettercapsource(unstable)(unfixed)1136448

Notes

https://github.com/bettercap/bettercap/issues/1263
https://github.com/bettercap/bettercap/commit/3731d5576cffae9eefe3721cd46a40933304129f (v2.41.7)

Search for package or bug name: Reporting problems