Junglewise Threat Intelligence

CVE-2026-5656: Wireshark path traversal in Configuration Profile import

CVE-2026-5656 · Severity: high · CVSS 7 · Published 2026-05-01

Technologies: Red Hat Enterprise Linux AppStream, Red Hat Enterprise Linux AppStream EUS. Vendors: Red Hat, Wireshark Foundation.

Executive brief

Wireshark, a widely used network protocol analyzer, is vulnerable to a security flaw in its configuration profile import feature. If a user is convinced to import a specially crafted ZIP file, an attacker can place malicious files on the user's computer. This could lead to the application crashing or the execution of unauthorized commands, potentially allowing an attacker to take control of the system when Wireshark is next launched.

Technical details

A path traversal vulnerability, specifically a 'Zip-Slip' flaw, exists in the WiresharkZipHelper::unzip() function within the Configuration Profile import feature. The application fails to validate that file paths extracted from a ZIP archive remain within the intended target directory, allowing an attacker to use '../' sequences to write files to arbitrary locations. On POSIX-compliant systems, an attacker can exploit this by planting a malicious Lua script in the local plugins directory (~/.local/lib/wireshark/plugins/), which Wireshark automatically executes upon its next startup. Exploitation requires a user to manually import a malformed ZIP file. The issue is resolved in versions 4.6.5 and 4.4.15.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.4, 4.4.0 to 4.4.14
  • Red Hat Red Hat Enterprise Linux AppStream (v. 10) 10.2
  • Red Hat Red Hat Enterprise Linux AppStream EUS (v. 10.0) 10.0

Timeline

  • 2026-04-29: advisory: Wireshark published vendor advisory wnpa-sec-2026-21
  • 2026-04-30: disclosed: Vulnerability reported to GitLab/Wireshark Foundation
  • 2026-05-01: advisory: CVE-2026-5656 published to NVD
  • 2026-05-26: patched: Red Hat released security updates for RHEL 10

References

Related threats