Double Free in Wireshark
Published Apr 30, 2026
7.5
HIGHCVSS 3.1
EPSS 0.34%
Description
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products
-
- Version 4.4.0StatusaffectedConstraints<4.4.15
- Version 4.6.0StatusaffectedConstraints<4.6.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | unaffected |
|
No data.
Red Hat Enterprise Linux 10
wireshark
Fix deferred
Red Hat Enterprise Linux 6
wireshark
Fix deferred
Red Hat Enterprise Linux 7
wireshark
Fix deferred
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.6.5 or above
Red Hat mitigation
To mitigate this issue, users should avoid opening untrusted or suspicious network capture files. Additionally, exercise caution when performing live packet captures on untrusted networks or from untrusted sources, as processing specially crafted packets could trigger the denial of service.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-5657 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2464039 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26326 Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/21113 issue-trackingpermissions-requiredExploitIssue TrackingThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/work_items/21113 exploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-5657
- https://www.cve.org/CVERecord?id=CVE-2026-5657
- https://www.wireshark.org/security/wnpa-sec-2026-20.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-5657 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464039 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26326 | Advisory | |
| https://gitlab.com/wireshark/wireshark/-/issues/21113 | issue-trackingpermissions-requiredExploitIssue TrackingThird Party Advisory | |
| https://gitlab.com/wireshark/wireshark/-/work_items/21113 | exploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-5657 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-5657 | ||
| https://www.wireshark.org/security/wnpa-sec-2026-20.html | Vendor Advisory |
Change history (0)
No recorded changes yet.