Heap-based Buffer Overflow in Wireshark
Published Apr 30, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products
-
Affected
- ≥ 4.4.0, < 4.4.15
- ≥ 4.6.0, < 4.6.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Wireshark Foundation | Wireshark | unaffected | Affected
|
No data.
Red Hat Enterprise Linux 10
wireshark
Fix deferred
Red Hat Enterprise Linux 6
wireshark
Fix deferred
Red Hat Enterprise Linux 7
wireshark
Fix deferred
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 4.6.5 or above
Red Hat mitigation
Users should avoid opening untrusted capture files or processing network traffic from untrusted sources with Wireshark. If Wireshark is not actively used on a system, consider removing the `wireshark` package to eliminate the attack surface.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-6529 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2464040 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26336 Advisory
- https://gitlab.com/wireshark/wireshark/-/work_items/21145 ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6529
- https://www.cve.org/CVERecord?id=CVE-2026-6529
- https://www.wireshark.org/security/wnpa-sec-2026-32.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6529 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464040 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26336 | Advisory | |
| https://gitlab.com/wireshark/wireshark/-/work_items/21145 | ExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6529 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6529 | ||
| https://www.wireshark.org/security/wnpa-sec-2026-32.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data