CVE-2025-13674
published 2025-11-26CVE-2025-13674: BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.11%
1.5th percentile
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.6.1-1 (forky) | wireshark 4.6.1-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.6.1-1 | 4.6.1-1 |
| wireshark_foundation | wireshark | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-13674: BPv7 dissector crash in Wireshark 4
osv·2025-11-26·CVSS 5.5
CVE-2025-13674 [MEDIUM] CVE-2025-13674: BPv7 dissector crash in Wireshark 4
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
GHSA
GHSA-3v8x-9546-ch2g: BPv7 dissector crash in Wireshark 4
ghsa_unreviewed·2025-11-26
CVE-2025-13674 [MEDIUM] CWE-824 GHSA-3v8x-9546-ch2g: BPv7 dissector crash in Wireshark 4
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
Red Hat
Wireshark: Wireshark: BPv7 dissector crash leads to denial of service
vendor_redhat·2025-11-26·CVSS 5.5
CVE-2025-13674 [MEDIUM] CWE-824 Wireshark: Wireshark: BPv7 dissector crash leads to denial of service
Wireshark: Wireshark: BPv7 dissector crash leads to denial of service
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
A flaw in the BPv7 (Bundle Protocol v7) dissector in Wireshark 4.6.0 can cause the application to crash when processing certain malformed packets or trace files. The bug was discovered during internal fuzzing and occurs due to a use-after-free memory error triggered while decoding BPv7 elements.
Statement: This flaw is rated as moderate because its impact is limited to a denial-of-service crash within the Wireshark application and does not allow remote code execution, memory corruption leading to privilege escalation, or compromise of system integrity. The vulnerability arises from a use-after-free condition in the BPv7 dissector, which can be triggered
GitLab
Access of Uninitialized Pointer in Wireshark
vendor_gitlab·2025-11-26·CVSS 5.5
CVE-2025-13674 [MEDIUM] CWE-824 Access of Uninitialized Pointer in Wireshark
Access of Uninitialized Pointer in Wireshark
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
Affected products: Wireshark
Affected versions: 4.6.0 (affected)
Solution: Upgrade to version 4.6.1 or above
Debian
CVE-2025-13674: wireshark - BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
vendor_debian·2025·CVSS 5.5
CVE-2025-13674 [MEDIUM] CVE-2025-13674: wireshark - BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
2025-11-26
Published