wireshark: RPCoRDMA dissector crash
Published Apr 12, 2023
7.5
HIGHCVSS 3.1
EPSS 4.62%
Description
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Affected products
-
- Version >=3.6.0, <3.6.13StatusaffectedConstraints-
- Version >=4.0.0, <4.0.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | n/a |
|
Configuration 1
Configuration 2
- 10.0
- 12.0
Configuration 3
- 36
- 37
- 38
No data.
Red Hat Enterprise Linux 6
wireshark
Out of support scope
Red Hat Enterprise Linux 7
wireshark
Out of support scope
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 4.62% (0.04620) | 91.42th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.62% (0.04620) | 90.48th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.28% (0.00280) | 51.06th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.75% (0.01752) | 81.07th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.17% (0.00166) | 35.22th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.14% (0.00139) | 50.99th | v3 (v2023.03.01) |
| Jul 17, 2024 | 0.10% (0.00100) | 41.79th | v3 (v2023.03.01) |
| Apr 18, 2024 | 0.09% (0.00093) | 38.80th | v3 (v2023.03.01) |
| Mar 12, 2024 | 0.07% (0.00074) | 30.20th | v3 (v2023.03.01) |
| Oct 21, 2023 | 0.06% (0.00059) | 23.37th | v3 (v2023.03.01) |
| Jun 16, 2023 | 0.07% (0.00065) | 26.72th | v3 (v2023.03.01) |
| Apr 30, 2023 | 0.06% (0.00061) | 23.93th | v3 (v2023.03.01) |
| Apr 22, 2023 | 0.06% (0.00055) | 20.79th | v3 (v2023.03.01) |
| Apr 15, 2023 | 0.04% (0.00045) | 12.22th | v3 (v2023.03.01) |
References (14)
- https://access.redhat.com/security/cve/CVE-2023-1992 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2186329 Issue Tracking
- https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1992.json Third Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/18852 ExploitIssue TrackingPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/04/msg00029.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00049.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EHLTD25WNQSPQNELX52UH6YLP4TBLKTT/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FZA7IMATNNQPLIM6WMRPM3T5ZY24NRR2/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFJERBHVWYLYWXO2B3V47QH66IEB6EZ3/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-1992
- https://security.gentoo.org/glsa/202309-02 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1992
- https://www.debian.org/security/2023/dsa-5429 vendor-advisoryThird Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2023-09.html Vendor Advisory
Change history (0)
No recorded changes yet.