Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6524

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 6.5

Описание

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

A flaw was found in Wireshark, a widely used network protocol analyzer. A remote attacker could exploit a vulnerability within the MySQL protocol dissector, the part of the software that interprets MySQL network communications. This could lead to a denial of service, causing the Wireshark application to crash and become unresponsive.

Меры по смягчению последствий

To mitigate this issue, avoid opening untrusted capture files or analyzing untrusted network traffic with Wireshark. Additionally, the MySQL dissector can be disabled to prevent processing of MySQL protocol data. This can be done by navigating to "Analyze > Enabled Protocols..." in Wireshark and unchecking "MySQL". This action does not require a restart of the Wireshark application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkFix deferred
Red Hat Enterprise Linux 7wiresharkFix deferred
Red Hat Enterprise Linux 8wiresharkFix deferred
Red Hat Enterprise Linux 9wiresharkFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2464016wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
nvd
3 месяца назад

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
debian
3 месяца назад

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 t ...

CVSS3: 5.5
github
3 месяца назад

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

CVSS3: 5.5
fstec
4 месяца назад

Уязвимость диссектора протокола MySQL анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызывать отказ в обслуживании

6.5 Medium

CVSS3