There is 41 CVEs filled in against tcpdump in Fedora (tracker bug: https://bugzilla.redhat.com/show_bug.cgi?id=1419114). Trying to backport all patches would be both cumbersome and error prone. I suggest we rebase to the newest upstream version 4.9.0 which is currently in rawhide.
I guess you're trying to follow https://fedoraproject.org/wiki/Updates_Policy#Security_fixes , so please tell us if any of the listed issues apply to this rebase:
tcpdump
Thanks for the answers, Martin. I'm +1 to this rebase request.
@jforbes changed the status to Closed
Closed