Back

MEDIUM

Improperly Controlled Sequential Memory Allocation in Wireshark

Published Apr 30, 2026

Description

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Affected products

Remediation

Vendor solution

Upgrade to version 4.6.5 or above

Red Hat mitigation

To mitigate this issue, users should avoid opening untrusted or suspicious packet capture files with Wireshark. Running Wireshark in a sandboxed environment can further limit the potential impact of processing malicious data.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 30, 2026
Updated Apr 30, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Apr 30, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 30, 2026