Denial of Service Vulnerability in Wireshark by The Wireshark Foundation
CVE-2026-5657

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-5657?

A vulnerability in Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 exists due to a flaw in the iLBC codec functionality. This flaw can be exploited to cause a crash in the application, leading to a denial of service. Attackers can take advantage of this vulnerability by sending specially crafted packets to an affected version of Wireshark, resulting in immediate service disruption. It is crucial for users of Wireshark to upgrade to the latest version to mitigate this risk and enhance their system's security.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexandre de Oliveira
.