CVE-2026-6524
published 2026-04-30CVE-2026-6524: MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.5th percentile
MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6f7g-wj5x-f3vq: MySQL protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6524 [MEDIUM] CWE-824 GHSA-6f7g-wj5x-f3vq: MySQL protocol dissector crash in Wireshark 4
MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Red Hat
wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6524 [MEDIUM] CWE-1286 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash
wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash
A flaw was found in Wireshark, a widely used network protocol analyzer. A remote attacker could exploit a vulnerability within the MySQL protocol dissector, the part of the software that interprets MySQL network communications. This could lead to a denial of service, causing the Wireshark application to crash and become unresponsive.
Mitigation: To mitigate this issue, avoid opening untrusted capture files or analyzing untrusted network traffic with Wireshark. Additionally, the MySQL dissector can be disabled to prevent processing of MySQL protocol data. This can be done by navigating to "Analyze > Enabled Protocols..." in Wireshark and unchecking "MySQL". This action does not require a restart of the Wireshark ap
GitLab
Access of Uninitialized Pointer in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6524 [MEDIUM] CWE-824 Access of Uninitialized Pointer in Wireshark
Access of Uninitialized Pointer in Wireshark
MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Alexandre de Oliveira
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash [fedora-42]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6524 [MEDIUM] CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash [fedora-42]
CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash [fedora-43]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6524 [MEDIUM] CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash [fedora-43]
CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6524 [MEDIUM] CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash
CVE-2026-6524 wireshark: Wireshark: Denial of Service via MySQL protocol dissector crash
MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published