Infinite loop in Wireshark - CVE-2025-11626

 

Infinite loop in Wireshark - CVE-2025-11626

Published: October 9, 2025 / Updated: October 14, 2025


Vulnerability identifier: #VU116853
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11626
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop in MONGO dissector. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

Wireshark
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Oracle Solaris
wireshark-help
wireshark-devel
wireshark-debugsource
wireshark-debuginfo
wireshark
libwsutil15
wireshark-ui-qt
libwireshark17
libwsutil15-debuginfo
libwiretap14-debuginfo
wireshark-ui-qt-debuginfo
libwiretap14
libwireshark17-debuginfo
wireshark-cli
wireshark-doc
wireshark (Debian package)

How to mitigate CVE-2025-11626

Install updates from vendor's website.

Wireshark - addressed in versions 4.2.14, 4.4.10
wireshark-help - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-devel - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debugsource - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debuginfo - addressed in versions 3.6.14-13, 4.4.10-1
wireshark - addressed in versions 3.6.14-13, 4.4.10-1
wireshark-debugsource - addressed in versions 3.6.24-150000.3.124.1, 4.2.14-150600.18.29.1
wireshark-debuginfo - addressed in versions 3.6.24-150000.3.124.1, 4.2.14-150600.18.29.1
libwsutil15 - update to 4.2.14-150600.18.29.1
wireshark-devel - update to 4.2.14-150600.18.29.1
wireshark-ui-qt - update to 4.2.14-150600.18.29.1
wireshark - update to 4.2.14-150600.18.29.1
libwireshark17 - update to 4.2.14-150600.18.29.1
libwsutil15-debuginfo - update to 4.2.14-150600.18.29.1
libwiretap14-debuginfo - update to 4.2.14-150600.18.29.1
wireshark-ui-qt-debuginfo - update to 4.2.14-150600.18.29.1
libwiretap14 - update to 4.2.14-150600.18.29.1
libwireshark17-debuginfo - update to 4.2.14-150600.18.29.1
wireshark - update to 4.4.9-2
wireshark-cli - update to 4.4.9-2
wireshark-devel - update to 4.4.9-2
wireshark-doc - update to 4.4.9-2
wireshark - addressed in versions 4.4.10-1.fc41, 4.6.0-1.fc42, 4.6.0-1.fc43
wireshark (Debian package) - update to 4.4.13-0+deb13u1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89

External References

Related Security Bulletins