CVE-2026-6537
published 2026-04-30CVE-2026-6537: ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.18%
7.9th percentile
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Stack-based Buffer Overflow in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6537 [MEDIUM] CWE-121 Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Duc Anh Nguyen
Red Hat
Wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6537 [MEDIUM] CWE-617 Wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash
Wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the ZigBee protocol dissector by crafting a malicious packet. This could lead to a crash of the Wireshark application, resulting in a denial of service (DoS) for the user.
Mitigation: To mitigate this issue, users can disable the ZigBee protocol dissector in Wireshark. This can be achieved by navigating to `Analyze > Enabled Protocols...` and unchecking the 'ZigBee' protocol. Alternatively, users should avoid opening untrusted capture files or analyzing untrusted live network traffic with Wireshark.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Packa
VulDB
Wireshark up to 4.4.14/4.6.4 ZigBee Protocol Dissector stack-based overflow (ID 21125 / WID-SEC-2026-1311)
vuldb·2026-05-01·CVSS 5.5
CVE-2026-6537 [MEDIUM] Wireshark up to 4.4.14/4.6.4 ZigBee Protocol Dissector stack-based overflow (ID 21125 / WID-SEC-2026-1311)
A vulnerability was found in Wireshark up to 4.4.14/4.6.4. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component ZigBee Protocol Dissector. This manipulation causes stack-based buffer overflow.
This vulnerability appears as CVE-2026-6537. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GHSA-rgw5-g2j8-66hh: ZigBee protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6537 [MEDIUM] CWE-121 GHSA-rgw5-g2j8-66hh: ZigBee protocol dissector crash in Wireshark 4
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6537 wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6537 [MEDIUM] CVE-2026-6537 wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash [fedora-all]
CVE-2026-6537 wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6537 Wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6537 [MEDIUM] CVE-2026-6537 Wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash
CVE-2026-6537 Wireshark: Wireshark: Denial of Service via ZigBee protocol dissector crash
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published