CVE-2026-7375
published 2026-04-30CVE-2026-7375: UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.19%
9.3th percentile
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wireshark: Wireshark: Denial of Service via UDS protocol dissector infinite loop
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-7375 [MEDIUM] CWE-835 Wireshark: Wireshark: Denial of Service via UDS protocol dissector infinite loop
Wireshark: Wireshark: Denial of Service via UDS protocol dissector infinite loop
A flaw was found in Wireshark. A remote attacker could exploit an infinite loop in the UDS (Unix Domain Socket) protocol dissector by crafting a malicious network packet. This could lead to a denial of service (DoS), making the Wireshark application unresponsive and unavailable to users.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 7) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 8) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 9) - Fix deferred
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-7375 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Jaime Cavero
GHSA
GHSA-q392-394v-mxrh: UDS protocol dissector infinite loop in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-7375 [MEDIUM] CWE-835 GHSA-q392-394v-mxrh: UDS protocol dissector infinite loop in Wireshark 4
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
No detection rules found.
No public exploits indexed.
2026-04-30
Published