Input validation error in Wireshark - CVE-2025-13499
Published: November 20, 2025 / Updated: November 28, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the Kafka dissector. A remote attacker can trick a victim to read a malformed packet trace file and perform a denial of service (DoS) attack.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Basesystem Module
Desktop Applications Module
Server Applications Module
openSUSE Leap
openEuler
Anolis OS
Oracle Solaris
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
wireshark (Red Hat package)
wireshark-help
wireshark
wireshark-debuginfo
wireshark-debugsource
wireshark-devel
libwiretap14
wireshark-ui-qt-debuginfo
wireshark-ui-qt
libwsutil15-debuginfo
libwsutil15
libwiretap14-debuginfo
libwireshark17
libwireshark17-debuginfo
wireshark-cli
wireshark-doc
wireshark (Debian package)
libwsutil17
libwiretap16-debuginfo
libwireshark19-debuginfo
libwireshark19
libwiretap16
libwsutil17-debuginfo
libvirt-daemon-common
libvirt-daemon-driver-interface
libvirt-daemon-qemu
libvirt-daemon-driver-network-debuginfo
libvirt-daemon-driver-storage-iscsi-debuginfo
libvirt-daemon-driver-storage-iscsi
libvirt-daemon-driver-storage-scsi-debuginfo
libvirt-client-qemu
libvirt-daemon-driver-storage-logical-debuginfo
libvirt-daemon-driver-nodedev-debuginfo
libvirt-daemon-plugin-sanlock-debuginfo
libvirt-daemon-driver-storage-disk
libvirt-daemon-plugin-lockd-debuginfo
libvirt-daemon-driver-interface-debuginfo
libvirt-daemon-config-network
libvirt-daemon-proxy-debuginfo
libvirt-daemon-driver-network
libvirt-daemon-hooks
libvirt-daemon-log
libvirt-daemon-driver-storage
libvirt-daemon-common-debuginfo
libvirt-daemon-driver-qemu-debuginfo
libvirt-client-debuginfo
libvirt-daemon-plugin-sanlock
libvirt-daemon
libvirt-daemon-driver-storage-rbd
libvirt-daemon-driver-storage-rbd-debuginfo
libvirt-doc
libvirt-daemon-xen
libvirt-daemon-driver-libxl
libvirt-daemon-driver-libxl-debuginfo
libvirt-daemon-driver-storage-mpath-debuginfo
libvirt-libs-debuginfo
libvirt-libs
libvirt-debugsource
libvirt-daemon-driver-storage-core
libvirt-daemon-config-nwfilter
libvirt-daemon-driver-nwfilter-debuginfo
libvirt-daemon-proxy
libvirt-daemon-lock-debuginfo
libvirt-daemon-driver-storage-mpath
libvirt-nss
libvirt-client
libvirt
libvirt-daemon-driver-secret-debuginfo
libvirt-daemon-driver-storage-core-debuginfo
libvirt-daemon-driver-storage-iscsi-direct
libvirt-devel
libvirt-daemon-driver-storage-scsi
libvirt-daemon-driver-nwfilter
libvirt-daemon-driver-storage-logical
libvirt-daemon-log-debuginfo
libvirt-daemon-plugin-lockd
libvirt-daemon-driver-storage-iscsi-direct-debuginfo
libvirt-daemon-driver-storage-disk-debuginfo
libvirt-daemon-driver-qemu
libvirt-nss-debuginfo
libvirt-daemon-driver-secret
libvirt-daemon-driver-nodedev
libvirt-daemon-debuginfo
libvirt-daemon-lock
How to mitigate CVE-2025-13499
wireshark (Red Hat package) - addressed in versions 3.4.10-1.el9_0.1, 3.4.10-4.el9_2.1, 3.4.10-7.el9_6.1, 3.4.10-8.el9_7.1, 4.4.2-3.el10_0.1, 4.4.2-4.el10_1.1
wireshark-help - addressed in versions 3.6.14-13, 4.4.10-2
wireshark - addressed in versions 3.6.14-13, 4.4.10-2
wireshark-debuginfo - addressed in versions 3.6.14-13, 4.4.10-2
wireshark-debugsource - addressed in versions 3.6.14-13, 4.4.10-2
wireshark-devel - addressed in versions 3.6.14-13, 4.4.10-2
wireshark-debuginfo - addressed in versions 3.6.24-150000.3.127.1, 4.2.14-150600.18.32.1, 4.6.4-150700.21.8.1
wireshark-debugsource - addressed in versions 3.6.24-150000.3.127.1, 4.2.14-150600.18.32.1, 4.6.4-150700.21.8.1
libwiretap14 - update to 4.2.14-150600.18.32.1
wireshark-ui-qt-debuginfo - addressed in versions 4.2.14-150600.18.32.1, 4.6.4-150700.21.8.1
wireshark-ui-qt - addressed in versions 4.2.14-150600.18.32.1, 4.6.4-150700.21.8.1
wireshark-devel - addressed in versions 4.2.14-150600.18.32.1, 4.6.4-150700.21.8.1
libwsutil15-debuginfo - update to 4.2.14-150600.18.32.1
libwsutil15 - update to 4.2.14-150600.18.32.1
libwiretap14-debuginfo - update to 4.2.14-150600.18.32.1
wireshark - addressed in versions 4.2.14-150600.18.32.1, 4.6.4-150700.21.8.1
libwireshark17 - update to 4.2.14-150600.18.32.1
libwireshark17-debuginfo - update to 4.2.14-150600.18.32.1
wireshark - update to 4.4.9-3
wireshark-cli - update to 4.4.9-3
wireshark-devel - update to 4.4.9-3
wireshark-doc - update to 4.4.9-3
wireshark (Debian package) - update to 4.4.13-0+deb13u1
libwsutil17 - update to 4.6.4-150700.21.8.1
libwiretap16-debuginfo - update to 4.6.4-150700.21.8.1
libwireshark19-debuginfo - update to 4.6.4-150700.21.8.1
libwireshark19 - update to 4.6.4-150700.21.8.1
libwiretap16 - update to 4.6.4-150700.21.8.1
libwsutil17-debuginfo - update to 4.6.4-150700.21.8.1
libvirt-daemon-common - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-interface - update to 11.0.0-150700.4.19.1
libvirt-daemon-qemu - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-network-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-scsi-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-client-qemu - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-logical-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nodedev-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-sanlock-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-disk - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-lockd-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-interface-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-config-network - update to 11.0.0-150700.4.19.1
libvirt-daemon-proxy-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-network - update to 11.0.0-150700.4.19.1
libvirt-daemon-hooks - update to 11.0.0-150700.4.19.1
libvirt-daemon-log - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage - update to 11.0.0-150700.4.19.1
libvirt-daemon-common-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-qemu-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-client-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-sanlock - update to 11.0.0-150700.4.19.1
libvirt-daemon - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-rbd - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-rbd-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-doc - update to 11.0.0-150700.4.19.1
libvirt-daemon-xen - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-libxl - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-libxl-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-mpath-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-libs-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-libs - update to 11.0.0-150700.4.19.1
libvirt-debugsource - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-core - update to 11.0.0-150700.4.19.1
libvirt-daemon-config-nwfilter - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nwfilter-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-proxy - update to 11.0.0-150700.4.19.1
libvirt-daemon-lock-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-mpath - update to 11.0.0-150700.4.19.1
libvirt-nss - update to 11.0.0-150700.4.19.1
libvirt-client - update to 11.0.0-150700.4.19.1
libvirt - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-secret-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-core-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi-direct - update to 11.0.0-150700.4.19.1
libvirt-devel - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-scsi - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nwfilter - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-logical - update to 11.0.0-150700.4.19.1
libvirt-daemon-log-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-plugin-lockd - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-iscsi-direct-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-storage-disk-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-qemu - update to 11.0.0-150700.4.19.1
libvirt-nss-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-secret - update to 11.0.0-150700.4.19.1
libvirt-daemon-driver-nodedev - update to 11.0.0-150700.4.19.1
libvirt-daemon-debuginfo - update to 11.0.0-150700.4.19.1
libvirt-daemon-lock - update to 11.0.0-150700.4.19.1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
External References
Related Security Bulletins
- Multiple vulnerabilities in Wireshark
- openEuler 24.03 LTS SP2 update for wireshark
- openEuler 24.03 LTS SP1 update for wireshark
- openEuler 24.03 LTS update for wireshark
- openEuler 22.03 LTS SP4 update for wireshark
- openEuler 22.03 LTS SP3 update for wireshark
- Anolis OS update for wireshark
- Red Hat Enterprise Linux 10 update for wireshark
- Red Hat Enterprise Linux 9 update for wireshark
- SUSE update for wireshark
- SUSE update for wireshark
- Red Hat Enterprise Linux 9 update for wireshark
- Red Hat Enterprise Linux 9 update for wireshark
- Red Hat Enterprise Linux 9 update for wireshark
- Red Hat Enterprise Linux 10 update for wireshark
- Multiple vulnerabilities in Oracle Solaris
- Debian update for wireshark
- openEuler 20.03 LTS SP4 update for wireshark
- SUSE update for wireshark