In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wireshark | Jun 6, 2019 | May 23, 2019 |
| Debian | — | Upgrade wireshark | Nov 2, 2020 | May 23, 2019 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 10, 2019 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/wireshark-common to version 2.6.9-11.4.10.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark to version 2.6.9-11.4.10.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark/tshark to version 2.6.9-11.4.10.0.1.2.0 on Solaris 11.4 | Jun 26, 2019 | May 23, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2019 |
| Ubuntu | — | Upgrade tsharkUpgrade libwireshark-dataUpgrade wireshark-commonUpgrade wireshark-gtkUpgrade wiresharkUpgrade libwscodecs2Upgrade libwireshark11Upgrade wireshark-qtUpgrade libwiretap8Upgrade libwsutil9 | Sep 17, 2019 | May 23, 2019 |
| Wireshark | — | Upgrade to Wireshark version 2.4.15Upgrade to Wireshark version 2.6.9Upgrade to Wireshark version 3.0.2 | May 27, 2019 | May 23, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub