Source: wireshark
Version: 4.6.6-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for wireshark.

CVE-2026-15163[0]:
| Multiple protocol dissector infinite loops in Wireshark 4.6.0 to
| 4.6.6 and 4.4.0 to 4.4.16 allow denial of service


CVE-2026-15164[1]:
| Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial
| of service


CVE-2026-15165[2]:
| TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of
| service


CVE-2026-15166[3]:
| IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15167[4]:
| DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15168[5]:
| BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16
| allows possible information disclosure


CVE-2026-15169[6]:
| UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15170[7]:
| Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15171[8]:
| SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0
| to 4.4.16 allows denial of service


CVE-2026-15172[9]:
| FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15173[10]:
| pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial
| of service


CVE-2026-15174[11]:
| Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to
| 4.6.6 and 4.4.0 to 4.4.16 allows denial of service


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15163
    https://www.cve.org/CVERecord?id=CVE-2026-15163
[1] https://security-tracker.debian.org/tracker/CVE-2026-15164
    https://www.cve.org/CVERecord?id=CVE-2026-15164
[2] https://security-tracker.debian.org/tracker/CVE-2026-15165
    https://www.cve.org/CVERecord?id=CVE-2026-15165
[3] https://security-tracker.debian.org/tracker/CVE-2026-15166
    https://www.cve.org/CVERecord?id=CVE-2026-15166
[4] https://security-tracker.debian.org/tracker/CVE-2026-15167
    https://www.cve.org/CVERecord?id=CVE-2026-15167
[5] https://security-tracker.debian.org/tracker/CVE-2026-15168
    https://www.cve.org/CVERecord?id=CVE-2026-15168
[6] https://security-tracker.debian.org/tracker/CVE-2026-15169
    https://www.cve.org/CVERecord?id=CVE-2026-15169
[7] https://security-tracker.debian.org/tracker/CVE-2026-15170
    https://www.cve.org/CVERecord?id=CVE-2026-15170
[8] https://security-tracker.debian.org/tracker/CVE-2026-15171
    https://www.cve.org/CVERecord?id=CVE-2026-15171
[9] https://security-tracker.debian.org/tracker/CVE-2026-15172
    https://www.cve.org/CVERecord?id=CVE-2026-15172
[10] https://security-tracker.debian.org/tracker/CVE-2026-15173
    https://www.cve.org/CVERecord?id=CVE-2026-15173
[11] https://security-tracker.debian.org/tracker/CVE-2026-15174
    https://www.cve.org/CVERecord?id=CVE-2026-15174

Regards,
Salvatore

Reply via email to