Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15171

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

A flaw was found in Wireshark's SSH (Secure Shell) protocol dissector. A remote attacker could craft a malicious network capture file that, when opened by a user, would cause the Wireshark application to crash. This vulnerability leads to a denial of service, preventing the user from analyzing network traffic.

Отчет

Moderate: A denial of service flaw exists in Wireshark's SSH protocol dissector, where processing a specially crafted network capture file can lead to application termination. This issue requires user interaction to open a malicious file, limiting its impact to the availability of the Wireshark application for network traffic analysis.

Меры по смягчению последствий

Users should avoid opening untrusted or suspicious network capture files with Wireshark. Running Wireshark in a sandboxed environment can further limit the impact of potential crashes. No direct configuration options are available to prevent this flaw without affecting Wireshark's core functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkOut of support scope
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2498296wireshark: Wireshark: Denial of service via SSH protocol dissector crash

EPSS

Процентиль: 2%
0.00122
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
nvd
около 1 месяца назад

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS3: 5.5
debian
около 1 месяца назад

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to ...

CVSS3: 5.5
redos
6 дней назад

Уязвимость wireshark

CVSS3: 5.5
redos
6 дней назад

Уязвимость wireshark

EPSS

Процентиль: 2%
0.00122
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2026-15171