Junglewise Threat Intelligence

CVE-2026-5403: Wireshark heap buffer overflow in SBC audio codec

CVE-2026-5403 · Severity: high · CVSS 7.8 · Published 2026-05-01

Technologies: Red Hat Enterprise Linux 10. Vendors: Red Hat, Wireshark Foundation.

Executive brief

Wireshark, a widely used network protocol analyzer, is vulnerable to a memory corruption issue when processing certain audio data. An attacker could exploit this by tricking a user into opening a specially crafted network capture file, potentially causing the application to crash or allowing the attacker to take control of the system. This affects users who have the SBC audio codec installed and use Wireshark to analyze Bluetooth or multimedia traffic.

Technical details

A heap-based buffer overflow exists in the codec_sbc_decode() function within plugins/codecs/sbc/sbc.c. The vulnerability is caused by a failure to decrement remaining-space counters (size_in and size_out) during a multi-frame decode loop, leading to an out-of-bounds write when an RTP packet contains more than approximately 256 SBC frames. An attacker can trigger this by providing a crafted pcapng file containing malformed RTP payloads. The exploit requires the SBC codec plugin to be compiled with libsbc; systems without this library are unaffected. Successful exploitation can result in application crashes (DoS) or arbitrary code execution under the context of the user running Wireshark or sharkd.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.4, 4.4.0 to 4.4.14
  • Red Hat Red Hat Enterprise Linux 10 All versions

Timeline

  • 2026-04-29: advisory: Wireshark published security advisory wnpa-sec-2026-16
  • 2026-04-30: disclosed: Initial CVE publication date
  • 2026-05-01: other: Red Hat bug report created
  • 2026-06-30: patched: Red Hat updated VEX documentation for REL 10

References