CVE-2026-6525
published 2026-05-02CVE-2026-6525: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.18%
8.0th percentile
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w582-36rx-qpx6: IEEE 802
ghsa_unreviewed·2026-05-02
CVE-2026-6525 [MEDIUM] CWE-476 GHSA-w582-36rx-qpx6: IEEE 802
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
VulDB
Wireshark up to 4.6.4 IEEE 802.11 Protocol Dissector null pointer dereference (EUVD-2026-26785 / WID-SEC-2026-1311)
vuldb·2026-05-02·CVSS 5.5
CVE-2026-6525 [MEDIUM] Wireshark up to 4.6.4 IEEE 802.11 Protocol Dissector null pointer dereference (EUVD-2026-26785 / WID-SEC-2026-1311)
A vulnerability, which was classified as problematic, has been found in Wireshark up to 4.6.4. The impacted element is an unknown function of the component IEEE 802.11 Protocol Dissector. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-6525. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GitLab
NULL Pointer Dereference in Wireshark
vendor_gitlab·2026-05-02·CVSS 5.5
CVE-2026-6525 [MEDIUM] CWE-476 NULL Pointer Dereference in Wireshark
NULL Pointer Dereference in Wireshark
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
Affected products: Wireshark
Affected versions: >=4.6.0, <4.6.5 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Nils Bagge
Red Hat
wireshark: NULL Pointer Dereference in Wireshark
vendor_redhat·2026-05-02·CVSS 5.5
CVE-2026-6525 [MEDIUM] CWE-476 wireshark: NULL Pointer Dereference in Wireshark
wireshark: NULL Pointer Dereference in Wireshark
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
A flaw was found in the IEEE 802.11 dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing a NULL pointer dereference, resulting in a denial of service.
Statement: This issue will cause a crash in Wireshark with no other security impact. Also, this flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with a moderate severity.
Mitigation: If the IEEE 802.11 protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable the protocol dissector when using "t
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6525 wireshark: NULL Pointer Dereference in Wireshark [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6525 [MEDIUM] CVE-2026-6525 wireshark: NULL Pointer Dereference in Wireshark [fedora-all]
CVE-2026-6525 wireshark: NULL Pointer Dereference in Wireshark [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6525 wireshark: NULL Pointer Dereference in Wireshark
bugzilla·2026-05-02·CVSS 5.5
CVE-2026-6525 [MEDIUM] CVE-2026-6525 wireshark: NULL Pointer Dereference in Wireshark
CVE-2026-6525 wireshark: NULL Pointer Dereference in Wireshark
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
2026-05-02
Published