Junglewise Threat Intelligence

CVE-2026-15163: Wireshark multiple protocol dissector infinite loops

CVE-2026-15163 · Severity: medium · CVSS 5.5 · Published 2026-07-08

Vendors: Wireshark Foundation.

Executive brief

Wireshark, a widely used network protocol analyzer, is vulnerable to a denial-of-service flaw. By tricking a user into opening a specially crafted network capture file, an attacker can cause the application to enter an infinite loop, making it unresponsive. This can disrupt network troubleshooting and security analysis operations.

Technical details

A vulnerability exists in multiple protocol dissectors within Wireshark where certain malformed packets can trigger an infinite loop (CWE-835). The root cause involves dissectors failing to properly advance the packet offset or exit loop conditions when encountering specific field configurations, such as in the MIH or MPEG DSM-CC dissectors. An attacker can exploit this by providing a malicious .pcap or .pcapng file that, when parsed by a user, causes the application to consume CPU resources indefinitely and hang. The issue was identified through automated fuzz testing and is addressed in Wireshark versions 4.6.7 and 4.4.17.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.6, 4.4.0 to 4.4.16

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References