Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11626

Опубликовано: 10 окт. 2025
Источник: redhat
CVSS3: 5.5

Описание

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

A flaw was found in Wireshark’s MONGO dissector. When processing certain malformed MONGO packets, the dissector could enter an infinite loop, leading to unbounded CPU consumption. This issue allows an attacker to cause a denial of service by sending a specially crafted packet on the network or by convincing a user to open a malicious capture file.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkOut of support scope
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2403225wireshark: MONGO dissector infinite loop

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
6 месяцев назад

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

CVSS3: 5.5
nvd
6 месяцев назад

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

CVSS3: 5.5
debian
6 месяцев назад

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to ...

suse-cvrf
5 месяцев назад

Security update for wireshark

CVSS3: 5.5
github
6 месяцев назад

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

5.5 Medium

CVSS3