CVE-2026-3203
published 2026-02-25CVE-2026-3203: RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.16%
5.3th percentile
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.6.4-1 (forky) | wireshark 4.6.4-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.4.14-0+deb13u1 | 4.4.14-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.4-1 | 4.6.4-1 |
| wireshark | wireshark | >= 4.4.0 < 4.4.14 | 4.4.14 |
| wireshark | wireshark | >= 4.6.0 < 4.6.4 | 4.6.4 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.14 | 4.4.14 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.4 | 4.6.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Buffer Over-read in Wireshark
vendor_gitlab·2026-02-25·CVSS 7.5
CVE-2026-3203 [HIGH] CWE-126 Buffer Over-read in Wireshark
Buffer Over-read in Wireshark
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.14 (affected)
Solution: Upgrade to version 4.6.4 or above
Red Hat
wireshark: Buffer Over-read in Wireshark
vendor_redhat·2026-02-25·CVSS 5.5
CVE-2026-3203 [MEDIUM] CWE-126 wireshark: Buffer Over-read in Wireshark
wireshark: Buffer Over-read in Wireshark
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
A flaw was found in the RF4CE Profile dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing a buffer over-read, resulting in a denial of service.
Statement: This issue will cause a crash in Wireshark with no other security impact. Also, this flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with a moderate severity.
Mitigation: If the RF4CE Profile protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable t
Debian
CVE-2026-3203: wireshark - RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to ...
vendor_debian·2026·CVSS 5.5
CVE-2026-3203 [MEDIUM] CVE-2026-3203: wireshark - RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to ...
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.6.4-1)
sid: resolved (fixed in 4.6.4-1)
trixie: resolved (fixed in 4.4.14-0+deb13u1)
OSV
CVE-2026-3203: RF4CE Profile protocol dissector crash in Wireshark 4
osv·2026-02-25·CVSS 7.5
CVE-2026-3203 [HIGH] CVE-2026-3203: RF4CE Profile protocol dissector crash in Wireshark 4
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
GHSA
GHSA-qrr9-2772-633f: RF4CE Profile protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-02-25
CVE-2026-3203 [MEDIUM] CWE-126 GHSA-qrr9-2772-633f: RF4CE Profile protocol dissector crash in Wireshark 4
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3203 wireshark: Buffer Over-read in Wireshark
bugzilla·2026-02-25·CVSS 7.5
CVE-2026-3203 [HIGH] CVE-2026-3203 wireshark: Buffer Over-read in Wireshark
CVE-2026-3203 wireshark: Buffer Over-read in Wireshark
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:9666 https://access.redhat.com/errata/RHSA-2026:9666
Wiz
CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0961 [MEDIUM] CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0961 :
Wireshark vulnerability analysis and mitigation
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-driver-storage-disk
libvirt-daemon-driver-storage-iscsi
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homeb
Wiz
CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-0959 [MEDIUM] CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0959 :
Wireshark vulnerability analysis and mitigation
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
wireshark-gnome
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homebrew Severity MEDIUM
Wiz
CVE-2026-3201 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3201 [MEDIUM] CVE-2026-3201 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3201 :
Wireshark vulnerability analysis and mitigation
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-client-qemu
libvirt-daemon-config-network
Sources
Alpine 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Ec
Wiz
CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.7
CVE-2026-0960 [MEDIUM] CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0960 :
Wireshark vulnerability analysis and mitigation
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Source : NVD
## 5.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-libs
libwireshark19
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Debian 12 Severity MEDIUM No Fix Added at: Jan
Wiz
CVE-2026-3202 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3202 [MEDIUM] CVE-2026-3202 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3202 :
Wireshark vulnerability analysis and mitigation
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-driver-interface
libvirt-daemon-driver-storage-rbd
Sources
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Homebrew Severity HIGH Has Fix Added at: Mar 03, 2026
Red Hat 6, 7 Severity MEDIUM No Fix Add
Wiz
CVE-2026-3203 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3203 [MEDIUM] CVE-2026-3203 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3203 :
Wireshark vulnerability analysis and mitigation
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 5.5
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon
libvirt-daemon-config-nwfilter
Sources
Alpine 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Echo Seve
Wiz
CVE-2026-0962 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0962 [MEDIUM] CVE-2026-0962 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0962 :
Wireshark vulnerability analysis and mitigation
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
libwiretap16
Sources
Alpine 3.20, 3.21, edge Severity MEDIUM No Fix Added at: Jan 22, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Jan 18, 2026
Debian 13, 14 Severity
2026-02-25
Published