CVE-2026-6531
published 2026-04-30CVE-2026-6531: SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.19%
8.6th percentile
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6531 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Sharon Brizinov
Red Hat
Wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6531 [MEDIUM] CWE-835 Wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop
Wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop
A flaw was found in Wireshark. The SANE (Scanner Access Now Easy) protocol dissector contains an infinite loop vulnerability. A local user processing specially crafted SANE protocol traffic, such as opening a malicious capture file, can trigger this flaw, leading to a denial of service (DoS) in Wireshark.
Mitigation: To mitigate this issue, users should avoid opening untrusted capture files or processing SANE protocol traffic from untrusted sources. If Wireshark is not actively used, consider removing the `wireshark` package to eliminate the attack surface. For Red Hat Enterprise Linux and Fedora, this can be done using `sudo dnf remove wireshark`. Warning: Removing Wireshark may impact network analysis cap
VulDB
Wireshark up to 4.4.14/4.6.4 SANE Protocol Dissector infinite loop (ID 21139 / WID-SEC-2026-1311)
vuldb·2026-05-01·CVSS 5.5
CVE-2026-6531 [MEDIUM] Wireshark up to 4.4.14/4.6.4 SANE Protocol Dissector infinite loop (ID 21139 / WID-SEC-2026-1311)
A vulnerability, which was classified as problematic, has been found in Wireshark up to 4.4.14/4.6.4. Impacted is an unknown function of the component SANE Protocol Dissector. This manipulation causes infinite loop.
This vulnerability is tracked as CVE-2026-6531. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-5mwh-vg7p-2624: SANE protocol dissector infinite loop in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6531 [MEDIUM] CWE-835 GHSA-5mwh-vg7p-2624: SANE protocol dissector infinite loop in Wireshark 4
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6531 wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6531 [MEDIUM] CVE-2026-6531 wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop [fedora-all]
CVE-2026-6531 wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6531 Wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6531 [MEDIUM] CVE-2026-6531 Wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop
CVE-2026-6531 Wireshark: Wireshark: Denial of Service via SANE protocol dissector infinite loop
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published