Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76919

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

A flaw was found in Wireshark. A remote attacker could exploit a denial of service vulnerability in the ESS protocol dissector by processing a specially crafted network packet. This could lead to the application crashing, preventing network traffic analysis. The impact is limited to the availability of the Wireshark application itself.

Отчет

This Moderate impact denial of service vulnerability affects Wireshark's ESS protocol dissector. An attacker can crash the application by providing a specially crafted network packet for analysis. The impact is limited to the availability of the Wireshark application, requiring user interaction to process the malicious input.

Меры по смягчению последствий

To mitigate this issue prior to patching, disable the ESS protocol dissector by running tshark --disable-protocol ess or unchecking ESS under Analyze > Enabled Protocols. Additionally, avoid opening packet capture files from untrusted sources and restrict live capture to trusted networks using host firewalls. On systems where packet analysis is non-essential, remove the wireshark package entirely or restrict execution permissions strictly to authorized administrators.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkAffected
Red Hat Enterprise Linux 6wiresharkOut of support scope
Red Hat Enterprise Linux 7wiresharkAffected
Red Hat Enterprise Linux 8wiresharkAffected
Red Hat Enterprise Linux 9wiresharkAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-457
https://bugzilla.redhat.com/show_bug.cgi?id=2520093wireshark: Wireshark: Denial of Service vulnerability in ESS protocol dissector

EPSS

Процентиль: 16%
0.00247
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
29 дней назад

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.3
nvd
29 дней назад

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.3
debian
29 дней назад

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...

CVSS3: 5.3
github
29 дней назад

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 5.3
fstec
около 1 месяца назад

Уязвимость анализатора протокола ESS анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 16%
0.00247
Низкий

6.5 Medium

CVSS3