CVE-2026-5657
published 2026-04-30CVE-2026-5657: iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.21%
10.8th percentile
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wireshark: Wireshark: Denial of service via iLBC codec crash
vendor_redhat·2026-04-30·CVSS 7.5
CVE-2026-5657 [HIGH] CWE-1286 Wireshark: Wireshark: Denial of service via iLBC codec crash
Wireshark: Wireshark: Denial of service via iLBC codec crash
A flaw was found in Wireshark. An attacker could trigger a crash in the iLBC (internet Low Bitrate Codec) component by processing a specially crafted network packet. This vulnerability could lead to a denial of service, preventing the Wireshark application from functioning.
Mitigation: To mitigate this issue, users should avoid opening untrusted or suspicious network capture files. Additionally, exercise caution when performing live packet captures on untrusted networks or from untrusted sources, as processing specially crafted packets could trigger the denial of service.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat
GitLab
Double Free in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-5657 [MEDIUM] CWE-415 Double Free in Wireshark
Double Free in Wireshark
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Alexandre de Oliveira
GHSA
GHSA-wvxj-3gq6-2mg4: iLBC codec crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-5657 [MEDIUM] CWE-415 GHSA-wvxj-3gq6-2mg4: iLBC codec crash in Wireshark 4
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5657 wireshark: Wireshark: Denial of service via iLBC codec crash [fedora-all]
bugzilla·2026-05-04·CVSS 7.5
CVE-2026-5657 [HIGH] CVE-2026-5657 wireshark: Wireshark: Denial of service via iLBC codec crash [fedora-all]
CVE-2026-5657 wireshark: Wireshark: Denial of service via iLBC codec crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5657 Wireshark: Wireshark: Denial of service via iLBC codec crash
bugzilla·2026-04-30·CVSS 7.5
CVE-2026-5657 [HIGH] CVE-2026-5657 Wireshark: Wireshark: Denial of service via iLBC codec crash
CVE-2026-5657 Wireshark: Wireshark: Denial of service via iLBC codec crash
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published