CVE-2026-6522
published 2026-04-30CVE-2026-6522: RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.4th percentile
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6522 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Sharon Brizinov
Red Hat
Wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6522 [MEDIUM] CWE-835 Wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop
Wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop
A flaw was found in Wireshark. The RPKI-Router protocol dissector contains an infinite loop. A remote attacker could exploit this by crafting a malicious RPKI-Router packet, leading to a denial of service (DoS) condition, making the Wireshark application unresponsive.
Mitigation: To reduce exposure, avoid opening untrusted network capture files. When analyzing live traffic, apply capture filters to exclude RPKI-Router protocol packets, or use display filters to prevent the vulnerable dissector from processing potentially malicious data. This operational control limits the application's exposure to crafted packets.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (R
GHSA
GHSA-3vq9-9j8h-qhv2: RPKI-Router protocol dissector infinite loop in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6522 [MEDIUM] CWE-835 GHSA-3vq9-9j8h-qhv2: RPKI-Router protocol dissector infinite loop in Wireshark 4
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6522 wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6522 [MEDIUM] CVE-2026-6522 wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop [fedora-all]
CVE-2026-6522 wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6522 Wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6522 [MEDIUM] CVE-2026-6522 Wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop
CVE-2026-6522 Wireshark: Wireshark: Denial of Service via RPKI-Router protocol dissector infinite loop
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published