The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rxcachefind() and rxcacheinsert().