Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0960

Опубликовано: 14 янв. 2026
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

A flaw was found in Wireshark. A local user could be affected by a denial of service when opening a specially crafted capture file containing HTTP3 protocol traffic. This vulnerability is caused by an infinite loop within the HTTP3 protocol dissector, leading to the application becoming unresponsive.

Отчет

This vulnerability is rated Moderate for Red Hat Enterprise Linux and Red Hat In-Vehicle OS. The flaw in the Wireshark HTTP3 protocol dissector can lead to a denial of service when processing a specially crafted HTTP3 packet. This affects systems where Wireshark is used to analyze network traffic, potentially causing the application to become unresponsive.

Меры по смягчению последствий

Users should avoid opening untrusted or suspicious packet capture files with Wireshark. This vulnerability is triggered by processing specially crafted HTTP3 packet captures, which can lead to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkFix deferred
Red Hat Enterprise Linux 7wiresharkFix deferred
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2429762Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop

EPSS

Процентиль: 3%
0.00014
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
3 месяца назад

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

CVSS3: 4.7
nvd
3 месяца назад

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

CVSS3: 4.7
debian
3 месяца назад

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 all ...

CVSS3: 4.7
github
3 месяца назад

HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service

CVSS3: 5.5
fstec
3 месяца назад

Уязвимость анализатора трафика компьютерных сетей Wireshark, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00014
Низкий

4.7 Medium

CVSS3