Infinite loop in Wireshark - CVE-2026-6523
Published: April 30, 2026
Wireshark
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in the GNW protocol dissector when processing a malformed packet or parsing a malformed packet trace file. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a malformed packet trace file to cause a denial of service.
User interaction is required to open a malformed packet trace file.