CVE-2026-6520
published 2026-04-30CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.17%
6.7th percentile
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop
vendor_redhat·2026-04-30·CVSS 7.5
CVE-2026-6520 [HIGH] CWE-606 Wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop
Wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop
A flaw was found in Wireshark. A remote attacker could exploit an infinite loop vulnerability in the OpenFlow v6 protocol dissector by sending a specially crafted packet. This could lead to a denial of service (DoS), making the Wireshark application unresponsive.
Mitigation: To mitigate this issue, avoid opening untrusted capture files or analyzing network traffic from untrusted sources with Wireshark. If the OpenFlow v6 protocol dissection is not required, it can be disabled within Wireshark's preferences to prevent processing of these packets. This can be done by navigating to "Analyze" -> "Enabled Protocols" and unchecking "OpenFlow v6". Restarting Wireshark is required for the changes to take eff
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6520 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Sharon Brizinov
GHSA
GHSA-55w5-h92f-5hwq: OpenFlow v6 protocol dissector infinite loop in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6520 [MEDIUM] CWE-835 GHSA-55w5-h92f-5hwq: OpenFlow v6 protocol dissector infinite loop in Wireshark 4
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6520 wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop [fedora-all]
bugzilla·2026-05-04·CVSS 7.5
CVE-2026-6520 [HIGH] CVE-2026-6520 wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop [fedora-all]
CVE-2026-6520 wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6520 Wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop
bugzilla·2026-04-30·CVSS 7.5
CVE-2026-6520 [HIGH] CVE-2026-6520 Wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop
CVE-2026-6520 Wireshark: Wireshark: Denial of Service via OpenFlow v6 protocol dissector infinite loop
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published