CVE-2026-6538
published 2026-04-30CVE-2026-6538: BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.18%
7.9th percentile
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Wireshark up to 4.4.14/4.6.4 BEEP Protocol Dissector stack-based overflow (ID 21120 / WID-SEC-2026-1311)
vuldb·2026-05-01·CVSS 5.5
CVE-2026-6538 [MEDIUM] Wireshark up to 4.4.14/4.6.4 BEEP Protocol Dissector stack-based overflow (ID 21120 / WID-SEC-2026-1311)
A vulnerability identified as critical has been detected in Wireshark up to 4.4.14/4.6.4. This affects an unknown part of the component BEEP Protocol Dissector. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is known as CVE-2026-6538. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
GHSA
GHSA-f67r-cw3c-gfg6: BEEP protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6538 [MEDIUM] CWE-121 GHSA-f67r-cw3c-gfg6: BEEP protocol dissector crash in Wireshark 4
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
GitLab
Stack-based Buffer Overflow in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6538 [MEDIUM] CWE-121 Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Sharon Brizinov
Red Hat
Wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6538 [MEDIUM] CWE-1286 Wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash
Wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash
A flaw was found in Wireshark. A remote attacker could exploit a crash in the BEEP (Blocks Extensible Exchange Protocol) dissector by crafting a malicious BEEP packet. This vulnerability leads to a Denial of Service (DoS), causing Wireshark to become unresponsive.
Mitigation: To mitigate this issue, disable the BEEP protocol dissector in Wireshark. This prevents the application from processing BEEP packets, thereby avoiding the vulnerability. This action can be performed within Wireshark's protocol preferences. Disabling the BEEP dissector will prevent analysis of BEEP protocol traffic.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6538 wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6538 [MEDIUM] CVE-2026-6538 wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash [fedora-all]
CVE-2026-6538 wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6538 Wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6538 [MEDIUM] CVE-2026-6538 Wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash
CVE-2026-6538 Wireshark: Wireshark: Denial of Service via BEEP protocol dissector crash
BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published