CVE-2026-15166
published 2026-07-08CVE-2026-15166: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
3.2th percentile
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash
vendor_redhat·2026-07-08·CVSS 5.5
CVE-2026-15166 [MEDIUM] CWE-476 Wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash
Wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark, a network protocol analyzer. An attacker could exploit this vulnerability by sending a specially crafted network packet, which would cause the IEEE 802.11 protocol dissector to crash. This issue results in a denial of service, making the Wireshark application unresponsive and unavailable to users.
Statement: This Moderate impact flaw in Wireshark allows a denial of service when processing specially crafted IEEE 802.11 network packets. The vulnerability affects the availability of the Wireshark application, potentially disrupting network analysis operations, and require
GitLab
Stack-based Buffer Overflow in Wireshark
vendor_gitlab·2026-07-08·CVSS 5.5
CVE-2026-15166 [MEDIUM] CWE-121 Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.17 (affected)
Solution: Upgrade to version 4.6.7 or above
Credit: Claude and Ada Logics
VulDB
Wireshark up to 4.4.16/4.6.6 IEEE 802.11 Protocol Dissector denial of service
vuldb·2026-07-08·CVSS 5.5
CVE-2026-15166 [MEDIUM] Wireshark up to 4.4.16/4.6.6 IEEE 802.11 Protocol Dissector denial of service
A vulnerability, which was classified as problematic, was found in Wireshark up to 4.4.16/4.6.6. This affects an unknown function of the component IEEE 802.11 Protocol Dissector. The manipulation results in denial of service.
This vulnerability is reported as CVE-2026-15166. The attack can be launched remotely. No exploit exists.
GHSA
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
ghsa_unreviewed·2026-07-08
CVE-2026-15166 [MEDIUM] CWE-121 IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15166 wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash [fedora-all]
bugzilla·2026-07-09·CVSS 5.5
CVE-2026-15166 [MEDIUM] CVE-2026-15166 wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash [fedora-all]
CVE-2026-15166 wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Bugzilla
CVE-2026-15166 Wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash
bugzilla·2026-07-08·CVSS 5.5
CVE-2026-15166 [MEDIUM] CVE-2026-15166 Wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash
CVE-2026-15166 Wireshark: Wireshark: Denial of Service via IEEE 802.11 protocol dissector crash
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
2026-07-08
Published