CVE-2025-13945
published 2025-12-03CVE-2025-13945: HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
3.1th percentile
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.2-1 | 4.6.2-1 |
| wireshark | wireshark | >= 4.6.0 < 4.6.2 | 4.6.2 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.1 | 4.6.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Improperly Controlled Sequential Memory Allocation in Wireshark
vendor_gitlab·2025-12-03·CVSS 5.5
CVE-2025-13945 [MEDIUM] CWE-1325 Improperly Controlled Sequential Memory Allocation in Wireshark
Improperly Controlled Sequential Memory Allocation in Wireshark
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, <4.6.1 (affected)
Solution: Upgrade to version 4.6.2 or above
Credit: Sébastien Féry
Red Hat
wireshark: Improperly Controlled Sequential Memory Allocation in Wireshark
vendor_redhat·2025-12-03·CVSS 5.5
CVE-2025-13945 [MEDIUM] CWE-770 wireshark: Improperly Controlled Sequential Memory Allocation in Wireshark
wireshark: Improperly Controlled Sequential Memory Allocation in Wireshark
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
A flaw was found in the HTTP3 dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing an excessive consumption of CPU and memory resources, resulting in a denial of service.
Statement: This vulnerability will cause a crash in Wireshark with no other security impact. Additionally, this issue can only be exploited when a specially crafted pcap file is processed. For these reasons, this flaw has been rated with a moderate severity.
Mitigation: If the HTTP3 protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI applicat
Debian
CVE-2025-13945: wireshark - HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
vendor_debian·2025·CVSS 5.5
CVE-2025-13945 [MEDIUM] CVE-2025-13945: wireshark - HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
OSV
CVE-2025-13945: HTTP3 dissector crash in Wireshark 4
osv·2025-12-03·CVSS 5.5
CVE-2025-13945 [MEDIUM] CVE-2025-13945: HTTP3 dissector crash in Wireshark 4
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
GHSA
GHSA-2q7x-94rj-f68w: HTTP3 dissector crash in Wireshark 4
ghsa_unreviewed·2025-12-03
CVE-2025-13945 [MEDIUM] CWE-1325 GHSA-2q7x-94rj-f68w: HTTP3 dissector crash in Wireshark 4
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-03
Published