Описание
Security update for wireshark
This update for wireshark fixes the following issues
- CVE-2026-3201: missing limit checks in USB HID protocol dissector's
parse_report_descriptorfunction can lead to memory exhaustion (bsc#1258907). - CVE-2026-3203: missing length checks in the RF4CE Profile protocol dissector can lead to illegal memory access and crash (bsc#1258909).
- CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757).
- CVE-2026-5401: AFP dissector crash (bsc#1263756).
- CVE-2026-5403: SBC audio codec crash (bsc#1263765).
- CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766).
- CVE-2026-5405: RDP dissector crash (bsc#1263767).
- CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754).
- CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753).
- CVE-2026-5408: BT-DHT dissector crash (bsc#1263752).
- CVE-2026-5409: Monero dissector crash (bsc#1263751).
- CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750).
- CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749).
- CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809).
- CVE-2026-5657: iLBC audio codec crash (bsc#1263747).
- CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746).
- CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745).
- CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744).
- CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743).
- CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742).
- CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741).
- CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739).
- CVE-2026-6529: iLBC audio codec crash (bsc#1263737).
- CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736).
- CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735).
- CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734).
- CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733).
- CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732).
- CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731).
- CVE-2026-6537: ZigBee dissector crash (bsc#1263729).
- CVE-2026-6538: BEEP dissector crash (bsc#1263728).
- CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762).
- CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726).
Changes for wireshark:
- Updated to 4.4.15
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1258907
- SUSE Bug 1258909
- SUSE Bug 1263726
- SUSE Bug 1263728
- SUSE Bug 1263729
- SUSE Bug 1263731
- SUSE Bug 1263732
- SUSE Bug 1263733
- SUSE Bug 1263734
- SUSE Bug 1263735
- SUSE Bug 1263736
- SUSE Bug 1263737
- SUSE Bug 1263739
- SUSE Bug 1263741
- SUSE Bug 1263742
- SUSE Bug 1263743
- SUSE Bug 1263744
- SUSE Bug 1263745
- SUSE Bug 1263746
Описание
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-3201
- SUSE Bug 1258907
Описание
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-3203
- SUSE Bug 1258909
Описание
ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5299
- SUSE Bug 1263757
Описание
AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5401
- SUSE Bug 1263756
Описание
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Затронутые продукты
Ссылки
- CVE-2026-5403
- SUSE Bug 1263765
Описание
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5404
- SUSE Bug 1263766
Описание
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Затронутые продукты
Ссылки
- CVE-2026-5405
- SUSE Bug 1263767
Описание
FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5406
- SUSE Bug 1263754
Описание
SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5407
- SUSE Bug 1263753
Описание
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5408
- SUSE Bug 1263752
Описание
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5409
- SUSE Bug 1263751
Описание
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5653
- SUSE Bug 1263750
Описание
AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5654
- SUSE Bug 1263749
Описание
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Затронутые продукты
Ссылки
- CVE-2026-5656
- SUSE Bug 1263809
Описание
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-5657
- SUSE Bug 1263747
Описание
MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6519
- SUSE Bug 1263746
Описание
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6520
- SUSE Bug 1263745
Описание
OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6521
- SUSE Bug 1263744
Описание
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6522
- SUSE Bug 1263743
Описание
GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6523
- SUSE Bug 1263742
Описание
MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6524
- SUSE Bug 1263741
Описание
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6527
- SUSE Bug 1263739
Описание
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6529
- SUSE Bug 1263737
Описание
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6530
- SUSE Bug 1263736
Описание
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6531
- SUSE Bug 1263735
Описание
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6532
- SUSE Bug 1263734
Описание
Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6533
- SUSE Bug 1263733
Описание
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6534
- SUSE Bug 1263732
Описание
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6535
- SUSE Bug 1263731
Описание
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6537
- SUSE Bug 1263729
Описание
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6538
- SUSE Bug 1263728
Описание
HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6868
- SUSE Bug 1263762
Описание
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Затронутые продукты
Ссылки
- CVE-2026-6869
- SUSE Bug 1263726