Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5407

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

A flaw was found in Wireshark, a network protocol analyzer. An attacker could exploit this vulnerability by providing a specially crafted network capture file containing malicious SMB2 protocol data. This could trigger an infinite loop in Wireshark's SMB2 analysis component, leading to a denial of service (DoS) where the application becomes unresponsive.

Меры по смягчению последствий

To mitigate this issue, users should exercise caution and avoid opening untrusted or suspicious network capture files with Wireshark. Running Wireshark within a sandboxed environment, such as a container or a virtual machine, can further limit the potential impact of processing malicious data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkFix deferred
Red Hat Enterprise Linux 7wiresharkFix deferred
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2464020Wireshark: Wireshark: Denial of Service from malicious SMB2 protocol data

EPSS

Процентиль: 4%
0.00138
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
nvd
3 месяца назад

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
debian
3 месяца назад

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and ...

CVSS3: 5.5
github
3 месяца назад

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
fstec
5 месяцев назад

Уязвимость функций dissect_smb2_notify_data_out() и dissect_smb2_file_full_ea_info() диссектора протокола SMB2 анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызывать отказ в обслуживании

EPSS

Процентиль: 4%
0.00138
Низкий

5.5 Medium

CVSS3