CVE-2025-13946
published 2025-12-03CVE-2025-13946: MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
3.0th percentile
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.2-1 | 4.6.2-1 |
| wireshark | wireshark | >= 4.4.0 < 4.4.12 | 4.4.12 |
| wireshark | wireshark | >= 4.6.0 < 4.6.2 | 4.6.2 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.11 | 4.4.11 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.1 | 4.6.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_redhat·2025-12-03·CVSS 5.5
CVE-2025-13946 [MEDIUM] CWE-835 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
A flaw was found in the MEGACO dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing an infinite loop and resulting in a denial of service.
Statement: This vulnerability will cause a crash in Wireshark with no other security impact. Additionally, this issue can only be exploited when a specially crafted pcap file is processed. For these reasons, this flaw has been rated with a moderate severity.
Mitigation: If the MEGACO protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI applica
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2025-12-03·CVSS 5.5
CVE-2025-13946 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.11 (affected)
Solution: Upgrade to version 4.6.2, 4.4.12, or above
Debian
CVE-2025-13946: wireshark - MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 a...
vendor_debian·2025·CVSS 5.5
CVE-2025-13946 [MEDIUM] CVE-2025-13946: wireshark - MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 a...
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
GHSA
GHSA-5gwr-vqfx-wj2m: MEGACO dissector infinite loop in Wireshark 4
ghsa_unreviewed·2025-12-03
CVE-2025-13946 [MEDIUM] CWE-835 GHSA-5gwr-vqfx-wj2m: MEGACO dissector infinite loop in Wireshark 4
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
OSV
CVE-2025-13946: MEGACO dissector infinite loop in Wireshark 4
osv·2025-12-03·CVSS 5.5
CVE-2025-13946 [MEDIUM] CVE-2025-13946: MEGACO dissector infinite loop in Wireshark 4
MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-03
Published