Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6521

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

A flaw was found in Wireshark. The OpenFlow v5 protocol dissector contains an infinite loop vulnerability. A remote attacker could exploit this by sending a specially crafted packet, leading to a denial of service (DoS) condition, making the application unresponsive.

Меры по смягчению последствий

To reduce exposure, avoid analyzing untrusted network traffic or opening untrusted capture files with Wireshark. The OpenFlow v5 dissector can be disabled in Wireshark's protocol preferences to prevent the vulnerability from being triggered. This action may limit the ability to analyze OpenFlow v5 protocol traffic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkFix deferred
Red Hat Enterprise Linux 7wiresharkFix deferred
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2464027Wireshark: Wireshark: Denial of Service via OpenFlow v5 protocol dissector infinite loop

EPSS

Процентиль: 4%
0.00143
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
nvd
3 месяца назад

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
debian
3 месяца назад

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4. ...

CVSS3: 5.5
github
3 месяца назад

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
fstec
4 месяца назад

Уязвимость анализатора протокола OpenFlow v5 анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызывать отказ в обслуживании

EPSS

Процентиль: 4%
0.00143
Низкий

6.5 Medium

CVSS3