Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
Published Apr 30, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products
-
Affected
- ≥ 4.4.0, < 4.4.15
- ≥ 4.6.0, < 4.6.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Wireshark Foundation | Wireshark | unaffected | Affected
|
No data.
Red Hat Enterprise Linux 10
wireshark
Fix deferred
Red Hat Enterprise Linux 6
wireshark
Fix deferred
Red Hat Enterprise Linux 7
wireshark
Fix deferred
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.6.5 or above
Red Hat mitigation
To mitigate this issue, users should exercise caution and avoid opening K12 RF5 files from untrusted or unknown sources. As Wireshark is a tool for network analysis, it is recommended to only process files obtained from trusted origins.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-5404 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2464275 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26460 Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/21094 issue-trackingpermissions-requiredExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-5404
- https://www.cve.org/CVERecord?id=CVE-2026-5404
- https://www.wireshark.org/security/wnpa-sec-2026-15.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-5404 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464275 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26460 | Advisory | |
| https://gitlab.com/wireshark/wireshark/-/issues/21094 | issue-trackingpermissions-requiredExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-5404 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-5404 | ||
| https://www.wireshark.org/security/wnpa-sec-2026-15.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data