Junglewise Threat Intelligence

CVE-2026-15174: Wireshark heap buffer overflow in Catapult DCT2000 dissector

CVE-2026-15174 · Severity: medium · CVSS 5.5 · Published 2026-07-08

Vendors: Wireshark Foundation.

Executive brief

Wireshark, a widely used network protocol analyzer, is vulnerable to a crash when processing specifically crafted Catapult DCT2000 network trace files. An attacker could provide a malicious capture file to a user, which, when opened, causes the application to crash and stop functioning. This results in a denial of service, potentially disrupting network troubleshooting or security analysis activities.

Technical details

A heap-based buffer overflow exists in the Catapult DCT2000 protocol dissector (epan/dissectors/packet-catapult-dct2000.c) within the attach_fp_info() function. The vulnerability is caused by a lack of bounds checking on the 'no_ddi_entries' value read from a capture file header. An attacker can provide a crafted Catapult/DCT2000 text capture with an excessively large 'no_ddi_entries' value, causing subsequent loops to write past the fixed-size 'edch_ddi' and 'edch_macd_pdu_size' arrays. This corrupts the wmem block allocator's metadata, leading to a segmentation fault (SIGSEGV) during subsequent memory allocations. The issue is addressed by capping the 'no_ddi_entries' value at MAX_EDCH_DDIS.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.6, 4.4.0 to 4.4.16

Timeline

  • 2026-07-08: advisory: NVD publication date

References