Executive brief
Wireshark, a widely used network protocol analyzer, is vulnerable to a denial-of-service flaw. By tricking a user into opening a specially crafted network capture file, an attacker can cause the application to enter an infinite loop, making it unresponsive. This can disrupt network troubleshooting and security analysis operations.
Technical details
A vulnerability exists in multiple protocol dissectors within Wireshark where certain malformed packets can trigger an infinite loop (CWE-835). The root cause involves dissectors failing to properly advance the packet offset or exit loop conditions when encountering specific field configurations, such as in the MIH or MPEG DSM-CC dissectors. An attacker can exploit this by providing a malicious .pcap or .pcapng file that, when parsed by a user, causes the application to consume CPU resources indefinitely and hang. The issue was identified through automated fuzz testing and is addressed in Wireshark versions 4.6.7 and 4.4.17.
Affected products
- Wireshark Foundation Wireshark 4.6.0 to 4.6.6, 4.4.0 to 4.4.16
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory