Denial of Service Vulnerability in Wireshark by The Wireshark Foundation
CVE-2026-6531

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-6531?

A vulnerability in the SANE protocol dissector within Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 may lead to an infinite loop condition, causing the application to become unresponsive. Exploiting this vulnerability can result in a denial of service, effectively disrupting network analysis capabilities. Users of affected versions are advised to upgrade to the latest software release to mitigate potential impacts.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sharon Brizinov
.