Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published Apr 30, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products
-
- Version 4.4.0StatusaffectedConstraints<4.4.15
- Version 4.6.0StatusaffectedConstraints<4.6.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Wireshark Foundation | Wireshark | unaffected |
|
No data.
Red Hat Enterprise Linux 10
wireshark
Fix deferred
Red Hat Enterprise Linux 6
wireshark
Fix deferred
Red Hat Enterprise Linux 7
wireshark
Fix deferred
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.6.5 or above
Red Hat mitigation
To reduce exposure, avoid opening untrusted network capture files. When analyzing live traffic, apply capture filters to exclude RPKI-Router protocol packets, or use display filters to prevent the vulnerable dissector from processing potentially malicious data. This operational control limits the application's exposure to crafted packets.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-6522 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2464030 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26330 Advisory
- https://gitlab.com/wireshark/wireshark/-/work_items/21186 exploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6522
- https://www.cve.org/CVERecord?id=CVE-2026-6522
- https://www.wireshark.org/security/wnpa-sec-2026-42.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6522 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464030 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26330 | Advisory | |
| https://gitlab.com/wireshark/wireshark/-/work_items/21186 | exploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6522 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6522 | ||
| https://www.wireshark.org/security/wnpa-sec-2026-42.html | Vendor Advisory |
Change history (0)
No recorded changes yet.