CVE-2025-1492
published 2025-02-20CVE-2025-1492: Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.28%
20.0th percentile
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.4.4-1 (forky) | wireshark 4.4.4-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.4.4-1 | 4.4.4-1 |
| wireshark | wireshark | >= 0 < 4.4.4-1 | 4.4.4-1 |
| wireshark | wireshark | 4.2.0 – 4.2.10 | — |
| wireshark | wireshark | 4.4.0 – 4.4.3 | — |
| wireshark_foundation | wireshark | >= 4.2.0 < 4.2.11 | 4.2.11 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.4 | 4.4.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-1492: Bundle Protocol and CBOR dissector crashes in Wireshark 4
osv·2025-02-20·CVSS 7.5
CVE-2025-1492 [HIGH] CVE-2025-1492: Bundle Protocol and CBOR dissector crashes in Wireshark 4
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
GHSA
GHSA-hrqm-vf6v-j4gp: Bundle Protocol and CBOR dissector crashes in Wireshark 4
ghsa_unreviewed·2025-02-20
CVE-2025-1492 [HIGH] CWE-674 GHSA-hrqm-vf6v-j4gp: Bundle Protocol and CBOR dissector crashes in Wireshark 4
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
Red Hat
wireshark: Uncontrolled Recursion in Wireshark
vendor_redhat·2025-02-20·CVSS 7.8
CVE-2025-1492 [HIGH] CWE-674 wireshark: Uncontrolled Recursion in Wireshark
wireshark: Uncontrolled Recursion in Wireshark
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
A flaw was found in Wireshark. Bundle Protocol and CBOR dissector crashes in Wireshark allow denial of service via packet injection or crafted capture file.
Statement: No any Red Hat offerings are impacted by this vulnerability.
Mitigation: No mitigation is available for this issue other than updating the affected package to the version containing the fix. However, by disabling BP and avoiding opening capture files from non trusted sources reduces the risk of triggering this vulnerability and crashing Wireshark.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Packa
GitLab
Uncontrolled Recursion in Wireshark
vendor_gitlab·2025-02-20·CVSS 7.5
CVE-2025-1492 [HIGH] CWE-674 Uncontrolled Recursion in Wireshark
Uncontrolled Recursion in Wireshark
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
Affected products: Wireshark
Affected versions: >=4.4.0, =4.2.0, <4.2.11 (affected)
Solution: Upgrade to version 4.4.4, 4.2.11 or above.
Credit: OSS-Fuzz
Debian
CVE-2025-1492: wireshark - Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0...
vendor_debian·2025·CVSS 7.8
CVE-2025-1492 [HIGH] CVE-2025-1492: wireshark - Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0...
Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 4.4.4-1)
sid: resolved (fixed in 4.4.4-1)
trixie: resolved (fixed in 4.4.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-20
Published