Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0959

Опубликовано: 14 янв. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

A flaw was found in Wireshark. A remote attacker could exploit a crash in the IEEE 802.11 protocol dissector by crafting a malicious network packet. This vulnerability leads to a denial of service, making the Wireshark application unavailable.

Отчет

This vulnerability is rated Moderate for Red Hat. An out-of-bounds write flaw in the IEEE 802.11 protocol dissector of Wireshark can lead to a denial of service. Exploitation requires user interaction, as a malicious packet capture file must be opened, and has high attack complexity, limiting the overall impact.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening untrusted or suspicious packet capture files with Wireshark. Limiting the use of Wireshark to trusted environments and only processing network traffic from known sources can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkFix deferred
Red Hat Enterprise Linux 7wiresharkFix deferred
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2429766Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash

EPSS

Процентиль: 7%
0.00025
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS3: 5.3
nvd
3 месяца назад

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS3: 5.3
debian
3 месяца назад

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4 ...

CVSS3: 5.3
github
3 месяца назад

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость анализатора трафика компьютерных сетей Wireshark, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 7%
0.00025
Низкий

5.3 Medium

CVSS3