Input validation error in Wireshark - CVE-2025-9817

 

Input validation error in Wireshark - CVE-2025-9817

Published: August 29, 2025 / Updated: September 15, 2025


Vulnerability identifier: #VU114556
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-9817
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the SSH dissector. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Wireshark
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Basesystem Module
Desktop Applications Module
Server Applications Module
openSUSE Leap
openEuler
Anolis OS
Oracle Solaris
wireshark
libwireshark17-debuginfo
wireshark-ui-qt
wireshark-debuginfo
libwsutil15-debuginfo
libwsutil15
libwiretap14-debuginfo
wireshark-ui-qt-debuginfo
libwiretap14
libwireshark17
wireshark-debugsource
wireshark-devel
wireshark (Red Hat package)
wireshark-help
wireshark-doc
wireshark-cli
wireshark (Debian package)
libwsutil17
libwireshark19-debuginfo
libwireshark19
libwiretap16
libwiretap16-debuginfo
libwsutil17-debuginfo
libvirt-daemon-driver-storage-iscsi-debuginfo
libvirt-daemon-driver-network-debuginfo
libvirt-daemon-common
libvirt-daemon-driver-interface
libvirt-daemon-qemu
libvirt-daemon-driver-storage-iscsi
libvirt-daemon-driver-storage-scsi-debuginfo
libvirt-client-qemu
libvirt-daemon-driver-storage-logical-debuginfo
libvirt-daemon-driver-nodedev-debuginfo
libvirt-daemon-plugin-sanlock-debuginfo
libvirt-daemon-driver-storage-disk
libvirt-daemon-plugin-lockd-debuginfo
libvirt-daemon-driver-interface-debuginfo
libvirt-daemon-config-network
libvirt-daemon-driver-libxl
libvirt-daemon-proxy-debuginfo
libvirt-daemon-driver-network
libvirt-daemon-hooks
libvirt-daemon-log
libvirt-daemon-driver-storage
libvirt-daemon-common-debuginfo
libvirt-daemon-driver-qemu-debuginfo
libvirt-client-debuginfo
libvirt-daemon-plugin-sanlock
libvirt-daemon
libvirt-daemon-driver-storage-rbd
libvirt-daemon-driver-storage-rbd-debuginfo
libvirt-doc
libvirt-daemon-xen
libvirt-daemon-driver-libxl-debuginfo
libvirt-libs-debuginfo
libvirt-daemon-lock
libvirt-libs
libvirt-debugsource
libvirt-daemon-driver-storage-core
libvirt-daemon-config-nwfilter
libvirt-daemon-driver-nwfilter-debuginfo
libvirt-daemon-proxy
libvirt-daemon-lock-debuginfo
libvirt-daemon-driver-storage-mpath
libvirt-nss
libvirt-client
libvirt
libvirt-daemon-driver-secret-debuginfo
libvirt-daemon-driver-storage-core-debuginfo
libvirt-devel
libvirt-daemon-driver-storage-iscsi-direct
libvirt-daemon-debuginfo
libvirt-daemon-driver-nodedev
libvirt-daemon-driver-secret
libvirt-nss-debuginfo
libvirt-daemon-driver-qemu
libvirt-daemon-driver-storage-disk-debuginfo
libvirt-daemon-driver-storage-iscsi-direct-debuginfo
libvirt-daemon-plugin-lockd
libvirt-daemon-log-debuginfo
libvirt-daemon-driver-storage-logical
libvirt-daemon-driver-nwfilter
libvirt-daemon-driver-storage-scsi
libvirt-daemon-driver-storage-mpath-debuginfo

How to mitigate CVE-2025-9817

Install updates from vendor's website.

Wireshark - update to 4.4.9
wireshark - addressed in versions 4.2.13-150600.18.26.1, 4.6.4-150700.21.8.1
libwireshark17-debuginfo - update to 4.2.13-150600.18.26.1
wireshark-ui-qt - addressed in versions 4.2.13-150600.18.26.1, 4.6.4-150700.21.8.1
wireshark-debuginfo - addressed in versions 4.2.13-150600.18.26.1, 4.6.4-150700.21.8.1
libwsutil15-debuginfo - update to 4.2.13-150600.18.26.1
libwsutil15 - update to 4.2.13-150600.18.26.1
libwiretap14-debuginfo - update to 4.2.13-150600.18.26.1
wireshark-ui-qt-debuginfo - addressed in versions 4.2.13-150600.18.26.1, 4.6.4-150700.21.8.1
libwiretap14 - update to 4.2.13-150600.18.26.1
libwireshark17 - update to 4.2.13-150600.18.26.1
wireshark-debugsource - addressed in versions 4.2.13-150600.18.26.1, 4.6.4-150700.21.8.1
wireshark-devel - addressed in versions 4.2.13-150600.18.26.1, 4.6.4-150700.21.8.1
wireshark (Red Hat package) - addressed in versions 4.4.2-3.el10_0.2, 4.4.2-4.el10_1.2
wireshark - addressed in versions 4.4.7-2, 4.4.7-3
wireshark-debuginfo - addressed in versions 4.4.7-2, 4.4.7-3
wireshark-help - addressed in versions 4.4.7-2, 4.4.7-3
wireshark-devel - addressed in versions 4.4.7-2, 4.4.7-3
wireshark-debugsource - addressed in versions 4.4.7-2, 4.4.7-3
wireshark-doc - update to 4.4.9-1
wireshark-devel - update to 4.4.9-1
wireshark-cli - update to 4.4.9-1
wireshark - update to 4.4.9-1
wireshark (Debian package) - update to 4.4.13-0+deb13u1
libwsutil17 - update to 4.6.4-150700.21.8.1
libwireshark19-debuginfo - update to 4.6.4-150700.21.8.1
libwireshark19 - update to 4.6.4-150700.21.8.1
libwiretap16 - update to 4.6.4-150700.21.8.1
libwiretap16-debuginfo - update to 4.6.4-150700.21.8.1
libwsutil17-debuginfo - update to 4.6.4-150700.21.8.1
libvirt-daemon-driver-storage-iscsi-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-network-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-common - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-interface - update to 11.0.0-150700.4.19.1
libvirt-daemon-qemu - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-scsi-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-client-qemu - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-logical-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nodedev-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-sanlock-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-disk - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-lockd-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-interface-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-config-network - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-libxl - update to 11.0.0-150700.4.19.1
libvirt-daemon-proxy-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-network - update to 11.0.0-150700.4.19.1
libvirt-daemon-hooks - update to 11.0.0-150700.4.19.1
libvirt-daemon-log - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage - update to 11.0.0-150700.4.19.1
libvirt-daemon-common-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-qemu-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-client-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-sanlock - update to 11.0.0-150700.4.19.1
libvirt-daemon - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-rbd - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-rbd-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-doc - update to 11.0.0-150700.4.19.1
libvirt-daemon-xen - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-libxl-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-libs-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-lock - update to 11.0.0-150700.4.19.1
libvirt-libs - update to 11.0.0-150700.4.19.1
libvirt-debugsource - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-core - update to 11.0.0-150700.4.19.1
libvirt-daemon-config-nwfilter - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nwfilter-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-proxy - update to 11.0.0-150700.4.19.1
libvirt-daemon-lock-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-mpath - update to 11.0.0-150700.4.19.1
libvirt-nss - update to 11.0.0-150700.4.19.1
libvirt-client - update to 11.0.0-150700.4.19.1
libvirt - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-secret-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-core-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-devel - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi-direct - update to 11.0.0-150700.4.19.1
libvirt-daemon-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nodedev - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-secret - update to 11.0.0-150700.4.19.1
libvirt-nss-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-qemu - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-disk-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi-direct-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-lockd - update to 11.0.0-150700.4.19.1
libvirt-daemon-log-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-logical - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nwfilter - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-scsi - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-mpath-debuginfo - update to 11.0.0-150700.4.19.1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89

External References

Related Security Bulletins