Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15169

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a specially crafted Universal Mobile Telecommunications System (UMTS) FP protocol packet. The flaw resides in the UMTS FP protocol dissector, which can lead to a crash of the Wireshark application. This can disrupt network analysis operations.

Отчет

This Moderate impact denial of service flaw in Wireshark's UMTS FP protocol dissector can be triggered by processing a specially crafted packet. While exploitable by a remote attacker, successful exploitation requires a user to either open a malicious capture file or actively capture network traffic containing the crafted packet. This limits the attack surface to scenarios where Wireshark is actively used for network analysis.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening or analyzing untrusted network capture files with Wireshark. Additionally, consider running Wireshark in a sandboxed environment to limit the potential impact of a crash. If Wireshark is not essential for daily operations, removing the wireshark package can eliminate the vulnerability, though this may affect other tools dependent on its libraries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2498295wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash

EPSS

Процентиль: 13%
0.00225
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
nvd
около 1 месяца назад

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
debian
около 1 месяца назад

UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 ...

CVSS3: 7.5
redos
6 дней назад

Уязвимость wireshark

CVSS3: 7.5
redos
6 дней назад

Уязвимость wireshark

EPSS

Процентиль: 13%
0.00225
Низкий

5.5 Medium

CVSS3