CVE-2025-9817
published 2025-09-03CVE-2025-9817: SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.19%
9.3th percentile
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.4.9-1 (forky) | wireshark 4.4.9-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.4.9-1 | 4.4.9-1 |
| wireshark | wireshark | 4.4.0 – 4.4.8 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.9 | 4.4.9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
NULL Pointer Dereference in Wireshark
vendor_gitlab·2025-09-03·CVSS 7.5
CVE-2025-9817 [HIGH] CWE-476 NULL Pointer Dereference in Wireshark
NULL Pointer Dereference in Wireshark
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
Affected products: Wireshark
Affected versions: >=4.4.0, <4.4.9 (affected)
Solution: Upgrade to version 4.4.9 or above
Red Hat
Wireshark: NULL Pointer Dereference in Wireshark
vendor_redhat·2025-09-03·CVSS 7.8
CVE-2025-9817 [HIGH] CWE-476 Wireshark: NULL Pointer Dereference in Wireshark
Wireshark: NULL Pointer Dereference in Wireshark
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
A flaw was found in Wireshark’s SSH dissector, caused by a missing NULL check in key exchange parameter handling. This vulnerability can trigger a segmentation fault when processing malformed SSH traffic or crafted capture files, potentially causing the application to crash and resulting in a denial of service.
Statement: This issue is considered Moderate rather than an Important flaw because its impact is limited to application availability and does not allow arbitrary code execution or information disclosure. The vulnerability leads to a segmentation fault in the SSH dissector, which can crash Wireshark or TShark, but only when the user opens a malicious capture fi
Debian
CVE-2025-9817: wireshark - SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
vendor_debian·2025·CVSS 7.8
CVE-2025-9817 [HIGH] CVE-2025-9817: wireshark - SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 4.4.9-1)
sid: resolved (fixed in 4.4.9-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
GHSA
GHSA-3mqq-9w3m-xpj8: SSH dissector crash in Wireshark 4
ghsa_unreviewed·2025-10-09
CVE-2025-9817 [HIGH] CWE-476 GHSA-3mqq-9w3m-xpj8: SSH dissector crash in Wireshark 4
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
OSV
CVE-2025-9817: SSH dissector crash in Wireshark 4
osv·2025-09-03·CVSS 7.5
CVE-2025-9817 [HIGH] CVE-2025-9817: SSH dissector crash in Wireshark 4
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-03
Published