CVE-2026-6529
published 2026-04-30CVE-2026-6529: iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
2.6th percentile
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Wireshark: Denial of Service via iLBC audio codec processing
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6529 [MEDIUM] CWE-237 wireshark: Wireshark: Denial of Service via iLBC audio codec processing
wireshark: Wireshark: Denial of Service via iLBC audio codec processing
A flaw was found in Wireshark. A remote attacker could exploit this vulnerability by providing a specially crafted iLBC audio codec. This could lead to a crash of the Wireshark application, resulting in a denial of service.
Mitigation: Users should avoid opening untrusted capture files or processing network traffic from untrusted sources with Wireshark. If Wireshark is not actively used on a system, consider removing the `wireshark` package to eliminate the attack surface.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 7) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 8) - Fix
GitLab
Heap-based Buffer Overflow in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6529 [MEDIUM] CWE-122 Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Alexandre de Oliveira
VulDB
Wireshark up to 4.4.14/4.6.4 iLBC Audio Codec heap-based overflow (WID-SEC-2026-1311)
vuldb·2026-05-01·CVSS 5.5
CVE-2026-6529 [MEDIUM] Wireshark up to 4.4.14/4.6.4 iLBC Audio Codec heap-based overflow (WID-SEC-2026-1311)
A vulnerability described as critical has been identified in Wireshark up to 4.4.14/4.6.4. This affects an unknown part of the component iLBC Audio Codec. Executing a manipulation can lead to heap-based buffer overflow.
The identification of this vulnerability is CVE-2026-6529. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-7prx-qj37-6gqq: iLBC audio codec crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6529 [MEDIUM] CWE-122 GHSA-7prx-qj37-6gqq: iLBC audio codec crash in Wireshark 4
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6529 wireshark: Wireshark: Denial of Service via iLBC audio codec processing [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6529 [MEDIUM] CVE-2026-6529 wireshark: Wireshark: Denial of Service via iLBC audio codec processing [fedora-all]
CVE-2026-6529 wireshark: Wireshark: Denial of Service via iLBC audio codec processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6529 wireshark: Wireshark: Denial of Service via iLBC audio codec processing
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6529 [MEDIUM] CVE-2026-6529 wireshark: Wireshark: Denial of Service via iLBC audio codec processing
CVE-2026-6529 wireshark: Wireshark: Denial of Service via iLBC audio codec processing
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published