Infinite Loop Vulnerability in Wireshark by the Wireshark Team
CVE-2026-6536

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-6536?

A vulnerability exists in Wireshark versions 4.6.0 to 4.6.4 related to the DLMS/COSEM protocol dissector. This issue can trigger an infinite loop during the analysis of certain network packets, preventing proper data handling and analysis. Attackers can exploit this vulnerability to cause denial-of-service conditions, leading to resource exhaustion for affected systems. Users are advised to update to the latest version to mitigate this vulnerability and ensure continuous network monitoring without disruptions.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brendan Coles
.