CVE-2026-6870
published 2026-04-30CVE-2026-6870: GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.16%
5.6th percentile
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Access of Uninitialized Pointer in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6870 [MEDIUM] CWE-824 Access of Uninitialized Pointer in Wireshark
Access of Uninitialized Pointer in Wireshark
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: TODO
Red Hat
Wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6870 [MEDIUM] CWE-237 Wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash
Wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash
A flaw was found in Wireshark. A user processing a specially crafted GSM RP protocol dissector file or network traffic could trigger a crash, leading to a denial of service.
Mitigation: To mitigate this issue, avoid opening untrusted network capture files or analyzing network traffic from untrusted sources with Wireshark. Users should exercise caution when handling files or network streams from unknown or suspicious origins.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 7) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 8) - Fix deferred
Package: wireshark (Red Hat Enterpr
GHSA
GHSA-2x3c-49j5-46pj: GSM RP protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6870 [MEDIUM] CWE-824 GHSA-2x3c-49j5-46pj: GSM RP protocol dissector crash in Wireshark 4
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6870 wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6870 [MEDIUM] CVE-2026-6870 wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash [fedora-all]
CVE-2026-6870 wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6870 Wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6870 [MEDIUM] CVE-2026-6870 Wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash
CVE-2026-6870 Wireshark: Wireshark: Denial of service via GSM RP protocol dissector crash
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published