HIGH
wireshark: Large loops in multiple dissectors
Published Feb 18, 2022
7.5
HIGHCVSS 3.1
EPSS 2.39%
Description
Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file
Affected products
-
- Version >=3.4.0, <3.4.12StatusaffectedConstraints-
- Version >=3.6.0, <3.6.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | n/a |
|
Configuration 1
Configuration 2
OR
- 34
- 35
Configuration 3
- 9.0
No data.
Red Hat Enterprise Linux 6
wireshark
Not affected
Red Hat Enterprise Linux 7
wireshark
Not affected
Red Hat Enterprise Linux 8
wireshark
Not affected
Red Hat Enterprise Linux 9
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2022-0585 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2054049 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15695 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0585.json Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00041.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRJ24JRKLA6XMDKLGVTOPM5KBBU4UHLN/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3DZD2JU56ZI4XV2B3HGVGA5PXQDNA5T/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0585
- https://security.gentoo.org/glsa/202210-04 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0585
- https://www.wireshark.org/security/wnpa-sec-2022-02
- https://www.wireshark.org/security/wnpa-sec-2022-02.html ExploitVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Feb 18, 2022
Updated Nov 3, 2025
Reserved Feb 14, 2022
Link CVE-2022-0585
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-15695 Assigner GitLab
Published Feb 18, 2022
Updated Nov 3, 2025
Exploited since n/a
Link EUVD-2022-15695