CVE-2026-5404
published 2026-05-01CVE-2026-5404: K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.2th percentile
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Wireshark up to 4.4.14/4.6.4 K12 RF5 File Parser buffer overflow (ID 21094 / Nessus ID 313009)
vuldb·2026-05-07·CVSS 5.5
CVE-2026-5404 [MEDIUM] Wireshark up to 4.4.14/4.6.4 K12 RF5 File Parser buffer overflow (ID 21094 / Nessus ID 313009)
A vulnerability was found in Wireshark up to 4.4.14/4.6.4. It has been rated as critical. Impacted is an unknown function of the component K12 RF5 File Parser. This manipulation causes buffer overflow.
The identification of this vulnerability is CVE-2026-5404. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-8rgp-w6w3-2537: K12 RF5 file parser crash in Wireshark 4
ghsa_unreviewed·2026-05-01
CVE-2026-5404 [MEDIUM] CWE-120 GHSA-8rgp-w6w3-2537: K12 RF5 file parser crash in Wireshark 4
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
GitLab
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
vendor_gitlab·2026-04-30·CVSS 4.7
CVE-2026-5404 [MEDIUM] CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: TODO
Red Hat
wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-5404 [MEDIUM] CWE-1286 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash
wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash
A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause the application to crash, leading to a denial of service. The attacker can achieve this by tricking a user into opening a specially crafted K12 RF5 file, which triggers a parser error.
Mitigation: To mitigate this issue, users should exercise caution and avoid opening K12 RF5 files from untrusted or unknown sources. As Wireshark is a tool for network analysis, it is recommended to only process files obtained from trusted origins.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 7) - Fix deferred
Package: wire
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5404 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-5404 [MEDIUM] CVE-2026-5404 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash [fedora-all]
CVE-2026-5404 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5404 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash
bugzilla·2026-05-01·CVSS 5.5
CVE-2026-5404 [MEDIUM] CVE-2026-5404 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash
CVE-2026-5404 wireshark: Wireshark: Denial of service due to K12 RF5 file parser crash
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-05-01
Published