CVE-2026-6527
published 2026-04-30CVE-2026-6527: ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
2.6th percentile
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Uncontrolled Recursion in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6527 [MEDIUM] CWE-674 Uncontrolled Recursion in Wireshark
Uncontrolled Recursion in Wireshark
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Alexandre de Oliveira
Red Hat
wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6527 [MEDIUM] CWE-193 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash
wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash
A flaw was found in Wireshark, a network protocol analyzer. A local user could be affected by this vulnerability if they open a specially crafted capture file containing malformed ASN.1 PER (Abstract Syntax Notation One Packed Encoding Rules) protocol data. This could lead to a crash of the Wireshark application, resulting in a denial of service.
Mitigation: Users should exercise caution when opening capture files from untrusted sources. Avoid opening any capture files that originate from unknown or suspicious origins to prevent triggering the denial of service vulnerability.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Pac
GHSA
GHSA-jqpv-h2g7-5cmm: ASN
ghsa_unreviewed·2026-04-30
CVE-2026-6527 [MEDIUM] CWE-674 GHSA-jqpv-h2g7-5cmm: ASN
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6527 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6527 [MEDIUM] CVE-2026-6527 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash [fedora-all]
CVE-2026-6527 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6527 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6527 [MEDIUM] CVE-2026-6527 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash
CVE-2026-6527 wireshark: Wireshark: Denial of Service due to ASN.1 PER protocol dissector crash
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published