CVE-2026-15170
published 2026-07-08CVE-2026-15170: Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
3.2th percentile
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Wireshark up to 4.4.16/4.6.6 Z39.50 Protocol Dissector denial of service
vuldb·2026-07-08·CVSS 5.5
CVE-2026-15170 [MEDIUM] Wireshark up to 4.4.16/4.6.6 Z39.50 Protocol Dissector denial of service
A vulnerability labeled as problematic has been found in Wireshark up to 4.4.16/4.6.6. Impacted is an unknown function of the component Z39.50 Protocol Dissector. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-15170. It is possible to launch the attack remotely. No exploit is available.
GHSA
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
ghsa_unreviewed·2026-07-08
CVE-2026-15170 [MEDIUM] CWE-122 Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Red Hat
wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash
vendor_redhat·2026-07-08·CVSS 5.5
CVE-2026-15170 [MEDIUM] CWE-131 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash
wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark's Z39.50 protocol dissector. A heap buffer overflow can occur when the dissector processes malformed Z39.50 records with partial directory entries, as the pre-allocated array size is calculated using floor division and does not account for additional partial entries. An attacker could exploit this by convincing a user to open a specially crafted packet capture file, causing Wireshark to crash. This results in a denial of service.
Statement: Moderate: A heap buffer overflow in Wireshark's Z39.50 protocol dissector can lead to a denial of service. This flaw requires user interactio
GitLab
Heap-based Buffer Overflow in Wireshark
vendor_gitlab·2026-07-08·CVSS 5.5
CVE-2026-15170 [MEDIUM] CWE-122 Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.17 (affected)
Solution: Upgrade to version 4.6.7 or above
Credit: Claude and Ada Logics
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15170 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash [fedora-all]
bugzilla·2026-07-09·CVSS 5.5
CVE-2026-15170 [MEDIUM] CVE-2026-15170 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash [fedora-all]
CVE-2026-15170 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Bugzilla
CVE-2026-15170 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash
bugzilla·2026-07-08·CVSS 5.5
CVE-2026-15170 [MEDIUM] CVE-2026-15170 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash
CVE-2026-15170 wireshark: Wireshark: Denial of service via Z39.50 protocol dissector crash
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
2026-07-08
Published