Back

MEDIUM

Improperly Controlled Sequential Memory Allocation in Wireshark

Published Apr 30, 2026

Description

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Affected products

Remediation

Vendor solution

Upgrade to version 4.6.5 or above

Red Hat mitigation

To mitigate this issue, users should avoid opening untrusted capture files or capturing network traffic from untrusted sources with Wireshark. If live capture of potentially malicious traffic is required, consider performing it within a sandboxed environment to contain any potential denial of service.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 30, 2026
Updated Apr 30, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Apr 30, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 30, 2026
ENISA EUVD
Assigner GitLab
Published Apr 30, 2026
Updated Apr 30, 2026
Exploited since n/a
EUVD-2026-26342