Infinite loop in Wireshark - CVE-2025-11626
Published: October 9, 2025 / Updated: October 14, 2025
Vulnerability identifier: #VU116853
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11626
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in MONGO dissector. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
Wireshark
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Oracle Solaris
wireshark-help
wireshark-devel
wireshark-debugsource
wireshark-debuginfo
wireshark
libwsutil15
wireshark-ui-qt
libwireshark17
libwsutil15-debuginfo
libwiretap14-debuginfo
wireshark-ui-qt-debuginfo
libwiretap14
libwireshark17-debuginfo
wireshark-cli
wireshark-doc
wireshark (Debian package)
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Oracle Solaris
wireshark-help
wireshark-devel
wireshark-debugsource
wireshark-debuginfo
wireshark
libwsutil15
wireshark-ui-qt
libwireshark17
libwsutil15-debuginfo
libwiretap14-debuginfo
wireshark-ui-qt-debuginfo
libwiretap14
libwireshark17-debuginfo
wireshark-cli
wireshark-doc
wireshark (Debian package)
How to mitigate CVE-2025-11626
Install updates from vendor's website.
Wireshark - addressed in versions 4.2.14, 4.4.10
wireshark-help - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-devel - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debugsource - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debuginfo - addressed in versions 3.6.14-13, 4.4.10-1
wireshark - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debugsource - addressed in versions 3.6.24-150000.3.124.1, 4.2.14-150600.18.29.1
wireshark-debuginfo - addressed in versions 3.6.24-150000.3.124.1, 4.2.14-150600.18.29.1
libwsutil15 - update to 4.2.14-150600.18.29.1
wireshark-devel - update to 4.2.14-150600.18.29.1
wireshark-ui-qt - update to 4.2.14-150600.18.29.1
wireshark - update to 4.2.14-150600.18.29.1
libwireshark17 - update to 4.2.14-150600.18.29.1
libwsutil15-debuginfo - update to 4.2.14-150600.18.29.1
libwiretap14-debuginfo - update to 4.2.14-150600.18.29.1
wireshark-ui-qt-debuginfo - update to 4.2.14-150600.18.29.1
libwiretap14 - update to 4.2.14-150600.18.29.1
libwireshark17-debuginfo - update to 4.2.14-150600.18.29.1
wireshark - update to 4.4.9-2
wireshark-cli - update to 4.4.9-2
wireshark-devel - update to 4.4.9-2
wireshark-doc - update to 4.4.9-2
wireshark - addressed in versions 4.4.10-1.fc41, 4.6.0-1.fc42, 4.6.0-1.fc43
wireshark (Debian package) - update to 4.4.13-0+deb13u1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
wireshark-help - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-devel - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debugsource - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debuginfo - addressed in versions 3.6.14-13, 4.4.10-1
wireshark - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debugsource - addressed in versions 3.6.24-150000.3.124.1, 4.2.14-150600.18.29.1
wireshark-debuginfo - addressed in versions 3.6.24-150000.3.124.1, 4.2.14-150600.18.29.1
libwsutil15 - update to 4.2.14-150600.18.29.1
wireshark-devel - update to 4.2.14-150600.18.29.1
wireshark-ui-qt - update to 4.2.14-150600.18.29.1
wireshark - update to 4.2.14-150600.18.29.1
libwireshark17 - update to 4.2.14-150600.18.29.1
libwsutil15-debuginfo - update to 4.2.14-150600.18.29.1
libwiretap14-debuginfo - update to 4.2.14-150600.18.29.1
wireshark-ui-qt-debuginfo - update to 4.2.14-150600.18.29.1
libwiretap14 - update to 4.2.14-150600.18.29.1
libwireshark17-debuginfo - update to 4.2.14-150600.18.29.1
wireshark - update to 4.4.9-2
wireshark-cli - update to 4.4.9-2
wireshark-devel - update to 4.4.9-2
wireshark-doc - update to 4.4.9-2
wireshark - addressed in versions 4.4.10-1.fc41, 4.6.0-1.fc42, 4.6.0-1.fc43
wireshark (Debian package) - update to 4.4.13-0+deb13u1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
External References
Related Security Bulletins
- Denial of service in Wireshark MONGO dissector
- Fedora 43 update for wireshark
- Fedora 41 update for wireshark
- Fedora 42 update for wireshark
- openEuler 24.03 LTS SP2 update for wireshark
- openEuler 24.03 LTS SP1 update for wireshark
- openEuler 24.03 LTS update for wireshark
- openEuler 22.03 LTS SP4 update for wireshark
- openEuler 22.03 LTS SP3 update for wireshark
- SUSE update for wireshark
- SUSE update for wireshark
- Anolis OS update for wireshark
- Multiple vulnerabilities in Oracle Solaris
- Debian update for wireshark
- openEuler 20.03 LTS SP4 update for wireshark