MEDIUM
wireshark: multiple (BPv6, OpenFlow, and Kafka protocol) dissector infinite loops
Published Jan 12, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.68%
Description
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
Affected products
-
Affected
- ≥ 3.6.0, < 3.6.10
- ≥ 4.0.0, < 4.0.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Wireshark Foundation | Wireshark | unknown | Affected
|
No data.
Red Hat Enterprise Linux 6
wireshark
Not affected
Red Hat Enterprise Linux 7
wireshark
Not affected
Red Hat Enterprise Linux 8
wireshark
Not affected
Red Hat Enterprise Linux 9
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Not affected | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- https://access.redhat.com/security/cve/CVE-2022-4345 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2160659 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51698 Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4345.json Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00007.html mailing-list
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGWIW6K64PKC375YAONYXKIVT2FDEDV3/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4345
- https://www.cve.org/CVERecord?id=CVE-2022-4345
- https://www.wireshark.org/security/wnpa-sec-2022-09.html Vendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jan 12, 2023
Updated Nov 3, 2025
Reserved Dec 7, 2022
Link CVE-2022-4345
CISA Vulnrichment
Updated Apr 8, 2025
GitHub
No data