CVE-2026-6523
published 2026-04-30CVE-2026-6523: GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.5th percentile
GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6523 [MEDIUM] CWE-835 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
A flaw was found in the GNW protocol dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing an infinite loop that leads to an excessive consumption of CPU resources, resulting in a denial of service.
Statement: This issue will cause a crash in Wireshark with no other security impact. Also, this flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with a moderate severity.
Mitigation: If the GNW protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6523 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Sharon Brizinov
GHSA
GHSA-5f5p-267h-86w3: GNW protocol dissector infinite loop in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6523 [MEDIUM] CWE-835 GHSA-5f5p-267h-86w3: GNW protocol dissector infinite loop in Wireshark 4
GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6523 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6523 [MEDIUM] CVE-2026-6523 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark [fedora-all]
CVE-2026-6523 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6523 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6523 [MEDIUM] CVE-2026-6523 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
CVE-2026-6523 wireshark: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published