Input validation error in Wireshark - CVE-2026-6527
Published: April 30, 2026
Wireshark
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ASN.1 PER dissectors when parsing malformed packets or packet trace files. A remote attacker can inject a malformed packet onto the wire or convince a victim to open a malformed packet trace file to cause a denial of service.
User interaction is required when exploitation is performed via a crafted packet trace file.