Back

HIGH

Heap-based Buffer Overflow in Wireshark

Published Apr 30, 2026

Description

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Affected products

Remediation

Vendor solution

Upgrade to version 4.6.5 or above

Red Hat statement

This issue will cause a crash in Wireshark and potentially result in code execution. This flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with an important severity.

Red Hat mitigation

If the SBC audio codec dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using "tshark", the command line tool. See the links below for instructions to disable a protocol in Wireshark, specifically the "Control Protocol Dissection" section and the "disabled_protos" configuration file option. https://www.wireshark.org/docs/wsug_html_chunked/ChCustProtocolDissectionSection.html https://www.wireshark.org/docs/wsug_html_chunked/ChAppFilesConfigurationSection.html

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 30, 2026
Updated Jul 15, 2026
Reserved Apr 2, 2026
CISA Vulnrichment
Updated May 1, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Apr 30, 2026