SB2026081366 - Multiple vulnerabilities in Wireshark



SB2026081366 - Multiple vulnerabilities in Wireshark

Published: August 13, 2026

Security Bulletin ID SB2026081366
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 28
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 28 vulnerabilities.


1) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the H.245 protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or convince someone to open a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a crafted packet capture file.


2) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the sharkd utility when parsing packet data. A remote attacker can inject a malformed packet onto the wire or convince a victim to open a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a crafted packet capture file.


3) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in sharkd utility when parsing malformed packets or malformed packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required to open a crafted packet capture file.


4) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the UMTS FP protocol dissector when parsing malformed packet data. A remote attacker can inject a malformed packet onto the wire or trick a victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation occurs via a crafted packet capture file.


5) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the RDP protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a crafted packet capture file.


6) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in TTX Logger file parser when parsing a malformed packet capture file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

User interaction is required to open a crafted packet capture file.


7) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the dissection engine reassembly logic when reassembling packets or parsing packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


8) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the BUSMASTER file parser when parsing a malformed packet capture file. A local user can trick the victim into opening a crafted file to cause a denial of service.

User interaction is required to open a crafted packet capture file.


9) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in Tektronix K12xx file parser when parsing a malformed packet capture file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

User interaction is required to open a crafted packet capture file.


10) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in ERF file parser when parsing a malformed packet capture file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

User interaction is required to open a crafted packet capture file.


11) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the bluetooth attribute protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or convince a victim to read a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


12) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Catapult DCT2000 file parser when parsing a malformed packet capture file. A remote attacker can trick the victim into opening a crafted packet capture file to cause a denial of service.

User interaction is required to open the crafted file.


13) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the C12.22 protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or convince a victim to open a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation occurs via a crafted packet capture file.


14) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in CMS protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


15) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Bluetooth AVRCP Profile protocol dissector when parsing malformed packets or crafted packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a crafted packet capture file.


16) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Kerberos protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a malformed packet capture file.


17) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in Bluetooth HFP Profile protocol dissector when parsing malformed packets or packet capture data. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a crafted packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


18) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Bluetooth BR/EDR FHS protocol dissector when parsing input. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


19) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the 3gpp phone log file parser when parsing malformed packet data or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


20) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Ixia IxVeriWave and Vector Informatik BLF file parsers when parsing a malformed packet capture file on Windows. A remote attacker can trick the victim into opening a specially crafted packet capture file to cause a denial of service.

User interaction is required to open a crafted packet capture file, and the issue affects Windows systems.


21) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the CMS protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


22) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the pcapng file parser when parsing input. A local user can trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required to open a crafted packet capture file.


23) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the SSH protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a crafted packet capture file.


24) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the ESS protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation relies on opening a crafted packet capture file.


25) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the X.509IF protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


26) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the RRC protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or convince a victim to open a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation is performed via a crafted packet capture file.


27) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the C12.22 protocol dissector when parsing malformed packets or packet capture files. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet capture file to cause a denial of service.

User interaction is required when exploitation uses a crafted packet capture file.


28) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in the Gammu DCT3 trace file parser when parsing a malformed packet capture file. A local user can trick the victim into opening a crafted file to cause a denial of service.

User interaction is required to open the crafted packet capture file.


Remediation

Install update from vendor's website.

References