CVE-2025-1492Uncontrolled Recursion in Foundation Wireshark

Severity
7.5HIGHNVD
CNA7.8
EPSS
0.1%
top 83.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0 to 4.2.10 allows denial of service via packet injection or crafted capture file

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5wireshark_foundation/wireshark4.4.04.4.4+1
Debianwireshark/wireshark< 4.4.4-1+1
NVDwireshark/wireshark4.2.04.2.10+1

🔴Vulnerability Details

3
OSV
CVE-2025-1492: Bundle Protocol and CBOR dissector crashes in Wireshark 42025-02-20
CVEList
Uncontrolled Recursion in Wireshark2025-02-20
GHSA
GHSA-hrqm-vf6v-j4gp: Bundle Protocol and CBOR dissector crashes in Wireshark 42025-02-20

📋Vendor Advisories

2
Red Hat
wireshark: Uncontrolled Recursion in Wireshark2025-02-20
Debian
CVE-2025-1492: wireshark - Bundle Protocol and CBOR dissector crashes in Wireshark 4.4.0 to 4.4.3 and 4.2.0...2025
CVE-2025-1492 — Uncontrolled Recursion | cvebase