Infinite loop in Wireshark - CVE-2021-22222
Published: June 9, 2021
Vulnerability identifier: #VU53976
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22222
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the DVB-S2-BB dissector. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
Wireshark
Arch Linux
Gentoo Linux
wireshark (Debian package)
Arch Linux
Gentoo Linux
wireshark (Debian package)
How to mitigate CVE-2021-22222
Install updates from vendor's website.
Wireshark - update to 3.4.6
wireshark (Debian package) - update to 3.4.10-0+deb11u1
wireshark (Debian package) - update to 3.4.10-0+deb11u1