CVE-2026-15169
published 2026-07-08CVE-2026-15169: UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.22%
12.2th percentile
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
vendor_redhat·2026-07-08·CVSS 7.5
CVE-2026-15169 [HIGH] CWE-1286 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a specially crafted Universal Mobile Telecommunications System (UMTS) FP protocol packet. The flaw resides in the UMTS FP protocol dissector, which can lead to a crash of the Wireshark application. This can disrupt network analysis operations.
Statement: This Moderate impact denial of service flaw in Wireshark's UMTS FP protocol dissector can be triggered by processing a specially crafted packet. While exploitable by a remote attacker, successful exploitation requires a user to either ope
GitLab
Heap-based Buffer Overflow in Wireshark
vendor_gitlab·2026-07-08·CVSS 5.5
CVE-2026-15169 [MEDIUM] CWE-122 Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.17 (affected)
Solution: Upgrade to version 4.6.7 or above
Credit: Claude and Ada Logics
GHSA
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
ghsa_unreviewed·2026-07-08
CVE-2026-15169 [MEDIUM] CWE-122 UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
VulDB
Wireshark up to 4.4.16/4.6.6 UMTS FP Protocol denial of service
vuldb·2026-07-08·CVSS 5.5
CVE-2026-15169 [MEDIUM] Wireshark up to 4.4.16/4.6.6 UMTS FP Protocol denial of service
A vulnerability was found in Wireshark up to 4.4.16/4.6.6 and classified as problematic. Affected is an unknown function of the component UMTS FP Protocol. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-15169. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15169 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash [fedora-all]
bugzilla·2026-07-09·CVSS 7.5
CVE-2026-15169 [HIGH] CVE-2026-15169 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash [fedora-all]
CVE-2026-15169 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Bugzilla
CVE-2026-15169 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
bugzilla·2026-07-08·CVSS 7.5
CVE-2026-15169 [HIGH] CVE-2026-15169 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
CVE-2026-15169 wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
2026-07-08
Published