Back

MEDIUM

Uncontrolled Recursion in Wireshark

Published Apr 30, 2026

Description

ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Affected products

Remediation

Vendor solution

Upgrade to version 4.6.5 or above

Red Hat statement

This issue will cause a crash in Wireshark with no other security impact. Also, this flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with a moderate severity.

Red Hat mitigation

If the ICMPv6 PvD protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using "tshark", the command line tool. See the links below for instructions to disable a protocol in Wireshark, specifically the "Control Protocol Dissection" section and the "disabled_protos" configuration file option. https://www.wireshark.org/docs/wsug_html_chunked/ChCustProtocolDissectionSection.html https://www.wireshark.org/docs/wsug_html_chunked/ChAppFilesConfigurationSection.html

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 30, 2026
Updated Apr 30, 2026
Reserved Apr 1, 2026
CISA Vulnrichment
Updated Apr 30, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 30, 2026
ENISA EUVD
Assigner GitLab
Published Apr 30, 2026
Updated Apr 30, 2026
Exploited since n/a
EUVD-2026-26315