CVE-2026-0962
published 2026-01-14CVE-2026-0962: SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.21%
10.7th percentile
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.6.3-1 (forky) | wireshark 4.6.3-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.3-1 | 4.6.3-1 |
| wireshark | wireshark | >= 4.2.2 < 4.4.13 | 4.4.13 |
| wireshark | wireshark | >= 4.6.0 < 4.6.3 | 4.6.3 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.13 | 4.4.13 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.3 | 4.6.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fxww-56j7-2rh4: SOME/IP-SD protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-01-14
CVE-2026-0962 [MEDIUM] CWE-787 GHSA-fxww-56j7-2rh4: SOME/IP-SD protocol dissector crash in Wireshark 4
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
OSV
CVE-2026-0962: SOME/IP-SD protocol dissector crash in Wireshark 4
osv·2026-01-14·CVSS 6.5
CVE-2026-0962 [MEDIUM] CVE-2026-0962: SOME/IP-SD protocol dissector crash in Wireshark 4
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
GitLab
Out-of-bounds Write in Wireshark
vendor_gitlab·2026-01-14·CVSS 6.5
CVE-2026-0962 [MEDIUM] CWE-787 Out-of-bounds Write in Wireshark
Out-of-bounds Write in Wireshark
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.13 (affected)
Solution: Upgrade to version 4.6.3 or above
Credit: Fatih Çelik
Red Hat
Wireshark: Wireshark: Denial of Service via SOME/IP-SD protocol dissector crash
vendor_redhat·2026-01-14·CVSS 5.3
CVE-2026-0962 [MEDIUM] CWE-787 Wireshark: Wireshark: Denial of Service via SOME/IP-SD protocol dissector crash
Wireshark: Wireshark: Denial of Service via SOME/IP-SD protocol dissector crash
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
A flaw was found in Wireshark. A remote attacker could entice a user to open a specially crafted packet capture file. This action would trigger a crash in the SOME/IP-SD protocol dissector, leading to a Denial of Service (DoS) for the affected system.
Statement: This vulnerability is rated Moderate for Red Hat. An out-of-bounds write in the Wireshark SOME/IP-SD protocol dissector can lead to a denial of service. Exploitation requires user interaction, as a victim must open a specially crafted packet trace file or capture malicious network traffic. Impact is limited to systems where Wireshark is instal
Debian
CVE-2026-0962: wireshark - SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4...
vendor_debian·2026·CVSS 5.3
CVE-2026-0962 [MEDIUM] CVE-2026-0962: wireshark - SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4...
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0961 [MEDIUM] CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0961 :
Wireshark vulnerability analysis and mitigation
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-driver-storage-disk
libvirt-daemon-driver-storage-iscsi
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homeb
Wiz
CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-0959 [MEDIUM] CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0959 :
Wireshark vulnerability analysis and mitigation
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
wireshark-gnome
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homebrew Severity MEDIUM
Wiz
CVE-2026-3201 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3201 [MEDIUM] CVE-2026-3201 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3201 :
Wireshark vulnerability analysis and mitigation
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-client-qemu
libvirt-daemon-config-network
Sources
Alpine 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Ec
Wiz
CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.7
CVE-2026-0960 [MEDIUM] CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0960 :
Wireshark vulnerability analysis and mitigation
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Source : NVD
## 5.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-libs
libwireshark19
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Debian 12 Severity MEDIUM No Fix Added at: Jan
Wiz
CVE-2026-3202 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3202 [MEDIUM] CVE-2026-3202 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3202 :
Wireshark vulnerability analysis and mitigation
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-driver-interface
libvirt-daemon-driver-storage-rbd
Sources
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Homebrew Severity HIGH Has Fix Added at: Mar 03, 2026
Red Hat 6, 7 Severity MEDIUM No Fix Add
Wiz
CVE-2026-3203 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3203 [MEDIUM] CVE-2026-3203 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3203 :
Wireshark vulnerability analysis and mitigation
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 5.5
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon
libvirt-daemon-config-nwfilter
Sources
Alpine 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Echo Seve
Wiz
CVE-2026-0962 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0962 [MEDIUM] CVE-2026-0962 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0962 :
Wireshark vulnerability analysis and mitigation
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
libwiretap16
Sources
Alpine 3.20, 3.21, edge Severity MEDIUM No Fix Added at: Jan 22, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Jan 18, 2026
Debian 13, 14 Severity
Bugzilla
CVE-2026-0962 Wireshark: Wireshark: Denial of Service via SOME/IP-SD protocol dissector crash
bugzilla·2026-01-14·CVSS 6.5
CVE-2026-0962 [MEDIUM] CVE-2026-0962 Wireshark: Wireshark: Denial of Service via SOME/IP-SD protocol dissector crash
CVE-2026-0962 Wireshark: Wireshark: Denial of Service via SOME/IP-SD protocol dissector crash
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
2026-01-14
Published