CVE-2025-13499
published 2025-11-21CVE-2025-13499: Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.10%
1.2th percentile
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.1-1 | 4.6.1-1 |
| wireshark | wireshark | >= 4.4.0 < 4.4.11 | 4.4.11 |
| wireshark_foundation | wireshark | — | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.11 | 4.4.11 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Access of Uninitialized Pointer in Wireshark
vendor_redhat·2025-11-21·CVSS 7.8
CVE-2025-13499 [HIGH] CWE-824 wireshark: Access of Uninitialized Pointer in Wireshark
wireshark: Access of Uninitialized Pointer in Wireshark
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
An uninitialized pointer access has been discovered in Wireshark. An attacker who can provide crafted input may be able to leverage this pointer access weakness to crash the application.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: wireshark (Red Hat Enterprise Linux 6) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 7) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 8) - Not affected
GitLab
Access of Uninitialized Pointer in Wireshark
vendor_gitlab·2025-11-21·CVSS 5.5
CVE-2025-13499 [MEDIUM] CWE-824 Access of Uninitialized Pointer in Wireshark
Access of Uninitialized Pointer in Wireshark
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
Affected products: Wireshark
Affected versions: 4.6.0 (affected), >=4.4.0, <4.4.11 (affected)
Solution: Upgrade to version 4.6.1, 4.4.11, or above
Debian
CVE-2025-13499: wireshark - Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of se...
vendor_debian·2025·CVSS 7.8
CVE-2025-13499 [HIGH] CVE-2025-13499: wireshark - Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of se...
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
GHSA
GHSA-6fqw-rh3v-4vph: Kafka dissector crash in Wireshark 4
ghsa_unreviewed·2025-11-21
CVE-2025-13499 [HIGH] CWE-824 GHSA-6fqw-rh3v-4vph: Kafka dissector crash in Wireshark 4
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
OSV
CVE-2025-13499: Kafka dissector crash in Wireshark 4
osv·2025-11-21·CVSS 5.5
CVE-2025-13499 [MEDIUM] CVE-2025-13499: Kafka dissector crash in Wireshark 4
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-21
Published