The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "260527178887615291491279372569759969730", "137708564359277337480054203088051610218", "298240062526909483142364042161448577666", "305938225022394359354304285237942418298" ] }, "id": "CVE-2018-16227-5a3d1b75", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/4846b3c5d0a850e860baf4f07340495d29837d09", "signature_version": "v1", "signature_type": "Line", "target": { "file": "print-802_11.c" }, "deprecated": false }, { "digest": { "function_hash": "281617910124428780885835396301876821598", "length": 1902.0 }, "id": "CVE-2018-16227-d32da9f1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/4846b3c5d0a850e860baf4f07340495d29837d09", "signature_version": "v1", "signature_type": "Function", "target": { "file": "print-802_11.c", "function": "ieee802_11_print" }, "deprecated": false } ] }