Source: wireshark Version: 4.6.6-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for wireshark. CVE-2026-15163[0]: | Multiple protocol dissector infinite loops in Wireshark 4.6.0 to | 4.6.6 and 4.4.0 to 4.4.16 allow denial of service CVE-2026-15164[1]: | Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial | of service CVE-2026-15165[2]: | TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of | service CVE-2026-15166[3]: | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15167[4]: | DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15168[5]: | BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 | allows possible information disclosure CVE-2026-15169[6]: | UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15170[7]: | Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15171[8]: | SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 | to 4.4.16 allows denial of service CVE-2026-15172[9]: | FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15173[10]: | pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial | of service CVE-2026-15174[11]: | Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to | 4.6.6 and 4.4.0 to 4.4.16 allows denial of service If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15163 https://www.cve.org/CVERecord?id=CVE-2026-15163 [1] https://security-tracker.debian.org/tracker/CVE-2026-15164 https://www.cve.org/CVERecord?id=CVE-2026-15164 [2] https://security-tracker.debian.org/tracker/CVE-2026-15165 https://www.cve.org/CVERecord?id=CVE-2026-15165 [3] https://security-tracker.debian.org/tracker/CVE-2026-15166 https://www.cve.org/CVERecord?id=CVE-2026-15166 [4] https://security-tracker.debian.org/tracker/CVE-2026-15167 https://www.cve.org/CVERecord?id=CVE-2026-15167 [5] https://security-tracker.debian.org/tracker/CVE-2026-15168 https://www.cve.org/CVERecord?id=CVE-2026-15168 [6] https://security-tracker.debian.org/tracker/CVE-2026-15169 https://www.cve.org/CVERecord?id=CVE-2026-15169 [7] https://security-tracker.debian.org/tracker/CVE-2026-15170 https://www.cve.org/CVERecord?id=CVE-2026-15170 [8] https://security-tracker.debian.org/tracker/CVE-2026-15171 https://www.cve.org/CVERecord?id=CVE-2026-15171 [9] https://security-tracker.debian.org/tracker/CVE-2026-15172 https://www.cve.org/CVERecord?id=CVE-2026-15172 [10] https://security-tracker.debian.org/tracker/CVE-2026-15173 https://www.cve.org/CVERecord?id=CVE-2026-15173 [11] https://security-tracker.debian.org/tracker/CVE-2026-15174 https://www.cve.org/CVERecord?id=CVE-2026-15174 Regards, Salvatore

