CVE-2026-6535
published 2026-04-30CVE-2026-6535: Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.14%
3.8th percentile
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: Wireshark: Denial of service via zlib decompression crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6535 [MEDIUM] CWE-409 wireshark: Wireshark: Denial of service via zlib decompression crash
wireshark: Wireshark: Denial of service via zlib decompression crash
A flaw was found in Wireshark's dissection engine. A remote attacker could exploit this vulnerability by sending a specially crafted packet. This could trigger a zlib decompression crash, leading to a denial of service and making the application unresponsive or causing it to terminate unexpectedly.
Mitigation: To mitigate this issue, users should avoid opening untrusted capture files or capturing network traffic from untrusted sources with Wireshark. If live capture of potentially malicious traffic is required, consider performing it within a sandboxed environment to contain any potential denial of service.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6)
GitLab
Improperly Controlled Sequential Memory Allocation in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6535 [MEDIUM] CWE-1325 Improperly Controlled Sequential Memory Allocation in Wireshark
Improperly Controlled Sequential Memory Allocation in Wireshark
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Brendan Coles
VulDB
Wireshark up to 4.4.14/4.6.4 zlib Decompression improperly controlled sequential memory allocation (ID 21097 / WID-SEC-2026-1311)
vuldb·2026-05-01·CVSS 5.5
CVE-2026-6535 [MEDIUM] Wireshark up to 4.4.14/4.6.4 zlib Decompression improperly controlled sequential memory allocation (ID 21097 / WID-SEC-2026-1311)
A vulnerability was found in Wireshark up to 4.4.14/4.6.4. It has been classified as problematic. This impacts an unknown function of the component zlib Decompression Handler. The manipulation leads to improperly controlled sequential memory allocation.
This vulnerability is documented as CVE-2026-6535. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-4mrg-698q-fxmg: Dissection engine zlib decompression crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6535 [MEDIUM] CWE-1325 GHSA-4mrg-698q-fxmg: Dissection engine zlib decompression crash in Wireshark 4
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6535 wireshark: Wireshark: Denial of service via zlib decompression crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6535 [MEDIUM] CVE-2026-6535 wireshark: Wireshark: Denial of service via zlib decompression crash [fedora-all]
CVE-2026-6535 wireshark: Wireshark: Denial of service via zlib decompression crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6535 wireshark: Wireshark: Denial of service via zlib decompression crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6535 [MEDIUM] CVE-2026-6535 wireshark: Wireshark: Denial of service via zlib decompression crash
CVE-2026-6535 wireshark: Wireshark: Denial of service via zlib decompression crash
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published