#1142268 wireshark: CVE-2026-15163 CVE-2026-15164 CVE-2026-15165 CVE-2026-15166 CVE-2026-15167 CVE-2026-15168 CVE-2026-15169 CVE-2026-15170 CVE-2026-15171 CVE-2026-15172 CVE-2026-15173 CVE-2026-15174 #1142268
- Package:
- src:wireshark
- Source:
- src:wireshark
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-07 20:29:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for wireshark. CVE-2026-15163[0]: | Multiple protocol dissector infinite loops in Wireshark 4.6.0 to | 4.6.6 and 4.4.0 to 4.4.16 allow denial of service CVE-2026-15164[1]: | Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial | of service CVE-2026-15165[2]: | TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of | service CVE-2026-15166[3]: | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15167[4]: | DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15168[5]: | BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 | allows possible information disclosure CVE-2026-15169[6]: | UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15170[7]: | Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15171[8]: | SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 | to 4.4.16 allows denial of service CVE-2026-15172[9]: | FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and | 4.4.0 to 4.4.16 allows denial of service CVE-2026-15173[10]: | pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial | of service CVE-2026-15174[11]: | Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to | 4.6.6 and 4.4.0 to 4.4.16 allows denial of service If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15163 https://www.cve.org/CVERecord?id=CVE-2026-15163 [1] https://security-tracker.debian.org/tracker/CVE-2026-15164 https://www.cve.org/CVERecord?id=CVE-2026-15164 [2] https://security-tracker.debian.org/tracker/CVE-2026-15165 https://www.cve.org/CVERecord?id=CVE-2026-15165 [3] https://security-tracker.debian.org/tracker/CVE-2026-15166 https://www.cve.org/CVERecord?id=CVE-2026-15166 [4] https://security-tracker.debian.org/tracker/CVE-2026-15167 https://www.cve.org/CVERecord?id=CVE-2026-15167 [5] https://security-tracker.debian.org/tracker/CVE-2026-15168 https://www.cve.org/CVERecord?id=CVE-2026-15168 [6] https://security-tracker.debian.org/tracker/CVE-2026-15169 https://www.cve.org/CVERecord?id=CVE-2026-15169 [7] https://security-tracker.debian.org/tracker/CVE-2026-15170 https://www.cve.org/CVERecord?id=CVE-2026-15170 [8] https://security-tracker.debian.org/tracker/CVE-2026-15171 https://www.cve.org/CVERecord?id=CVE-2026-15171 [9] https://security-tracker.debian.org/tracker/CVE-2026-15172 https://www.cve.org/CVERecord?id=CVE-2026-15172 [10] https://security-tracker.debian.org/tracker/CVE-2026-15173 https://www.cve.org/CVERecord?id=CVE-2026-15173 [11] https://security-tracker.debian.org/tracker/CVE-2026-15174 https://www.cve.org/CVERecord?id=CVE-2026-15174 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142268@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <mpolkorny@gmail.com> (supplier of updated wireshark package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 23 Aug 2026 12:34:57 -0300
Source: wireshark
Architecture: source
Version: 4.4.18-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Balint Reczey <balint@balintreczey.hu>
Changed-By: Matheus Polkorny <mpolkorny@gmail.com>
Closes: 1142268 1144924
Changes:
wireshark (4.4.18-0+deb13u1) trixie-security; urgency=medium
.
* Team upload.
* New upstream version 4.4.18 (Closes: #1142268, #1144924)
- CVE-2026-15163: Multiple loops in dissectors, allows DoS
- CVE-2026-15164: Crash in ciscodump, allows DoS
- CVE-2026-15166: IEEE 802.11 dissector crash, allows DoS
- CVE-2026-15167: DBS Etherwatch parser crash, allows DoS
- CVE-2026-15168: BLF parser, allows information disclosure
- CVE-2026-15169: UMTS FP dissector crash, allows DoS
- CVE-2026-15170: Z39.50 dissector crash, allows DoS
- CVE-2026-15171: SSH dissector crash, allows DoS
- CVE-2026-15172: FMP/NOTIFY dissector crash, allows DoS
- CVE-2026-15174: Catapult DCT2000 dissector crash, allows DoS
- CVE-2026-76879: C12.22 dissector crash, allows DoS
- CVE-2026-76880: RRC dissector crash, allows DoS
- CVE-2026-76881: CMS dissector crash, allows DoS
- CVE-2026-76882: Bluetooth Attribute dissector crash, allows DoS
- CVE-2026-76883: Catapult DCT2000 parser crash, allows DoS
- CVE-2026-76884: ERF parser crash, allows DoS
- CVE-2026-76885: Tektronix K12xx parser crash, allows DoS
- CVE-2026-76886: C12.22 dissector crash, allows DoS
- CVE-2026-76887: Dissection engine crash, allows DoS
- CVE-2026-76888: RDP dissector crash, allows DoS
- CVE-2026-76889: UMTS FP dissector crash, allows DoS
- CVE-2026-76890: Crash in sharkd, allows DoS
- CVE-2026-76891: Crash in sharkd, allows DoS
- CVE-2026-76917: Bluetooth AVRCP dissector crash, allows DoS
- CVE-2026-76918: SSH dissector crash, allows DoS
- CVE-2026-76919: ESS dissector crash, allows DoS
- CVE-2026-76920: 3gpp phone log parser crash, allows DoS
- CVE-2026-76921: CMS dissector crash, allows DoS
- CVE-2026-76922: Bluetooth BR/EDR FHS dissector crash, allows DoS
- CVE-2026-76923: Bluetooth HFP dissector crash, allows DoS
- CVE-2026-76924: Kerberos dissector crash, allows DoS
- CVE-2026-76926: BUSMASTER parser abnormal exit, allows DoS
- CVE-2026-76927: H.245 dissector crash, allows DoS
- CVE-2026-76928: X.509IF dissector crash, allows DoS
- CVE-2026-76929: Pcapng parser crash, allows DoS
Checksums-Sha1:
925f6788f2954b3e2a0b420f270ea5e687f3042d 3470 wireshark_4.4.18-0+deb13u1.dsc
1b56d51659ad0478667b7ab67f947c3d1361363d 50805713 wireshark_4.4.18.orig.tar.bz2
4896c826d13f5489ee9f94d3a6c1baec7e69a0ea 87340 wireshark_4.4.18-0+deb13u1.debian.tar.xz
44940dd539739d6719016220c56de89dcdeafa88 6495 wireshark_4.4.18-0+deb13u1_source.buildinfo
Checksums-Sha256:
04b2e2abeb34fe02de959d5543a040e5a6b782f2c6e2f8a2e355a0d3d4c9d878 3470 wireshark_4.4.18-0+deb13u1.dsc
5b0b9157e48edffbc2434a93d8cb8a8c67ee9cfc046188cd3664e96744a3697d 50805713 wireshark_4.4.18.orig.tar.bz2
1c82ac2c64c70a30a9090822317216225a9e6563f3799c4ac8df0aed547499ce 87340 wireshark_4.4.18-0+deb13u1.debian.tar.xz
6018d663dc52621611850b09b02e94a3c8dceb57e339b66e712b0997823b4e21 6495 wireshark_4.4.18-0+deb13u1_source.buildinfo
Files:
fcde05d15302194a4e6a1cc9f172e21a 3470 net optional wireshark_4.4.18-0+deb13u1.dsc
4b683419e6e76dfcb44cf467c9a892aa 50805713 net optional wireshark_4.4.18.orig.tar.bz2
7527fca341086b7b89304656972c3262 87340 net optional wireshark_4.4.18-0+deb13u1.debian.tar.xz
25a52819ac74a434c598b8d063338fdd 6495 net optional wireshark_4.4.18-0+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmqPqOUACgkQt4M9ggJ8
mQvhZw//c0oorCxpkLq+z4j/fosqWzJcrJ3zyiW1Ou/RLvCcI+Pl1Brcxk8ZeUSu
YyIxwmy4Dt7zkQzJf7RxrOZcpeq4+n4TD6mDgaKRoWRlhcZTW+Tdavo6m3sGpiLG
2OatgtEx9UKPQfCuZjPtIjd/IXqc+OvjDETUnSR8IYv2EJUKyuFuqrVYD3ocR2pb
mp553SdvjcS+yKWAQfNjMtJoeaZH/bV8Noy6XMBUOYE0iPulZowvjfCg4YFjKfdc
fS3kj60e9pwJFgyWgJPEpnfCiQBQhlnDbacGB5lF3vHzg0CISfJTadM+LVXpdDRe
NTNw6SQuQZxJdWqUv3khD9Nqr1oZetHZlzh84CsjSETkBTYvuEMMuLLDC0D5SASX
vQi2csyulpFOoX72jGPzSbyidjSbN193Y/jo3gD2ccuPvjYNp4fv2uyTxRW45A4J
Odt1WCUGjs1roDP/n0JfC35yDdFNcBmsFeA80PZW4rQrOhtS/84lmb8vsU8m5J1h
WfOhmBAg4Awh8hl1Hz8T8xlDdYt9yLbnjilI+3aYWn+fo9L6fW3X6UC83xjlY1p3
yKioBaLP5jpQRf9XQhL0Lf2+r80rWnuTuXu5WlMXVrj4EW7i8vhCD/cLAl1xYm1J
/tLASe+TbcwU0JRQE04/mYUcJcA9YsYs1CJ2Vvnqqo2SrR6/a80=
=WYG1
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142268@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <polkorny@debian.org> (supplier of updated wireshark package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 23:53:49 -0300
Source: wireshark
Architecture: source
Version: 4.6.9-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Matheus Polkorny <polkorny@debian.org>
Closes: 1142268 1144924 1149644
Changes:
wireshark (4.6.9-1) unstable; urgency=medium
.
* Team upload.
* New upstream release (Closes: #1142268, #1144924, #1149644)
- CVE-2026-15163: Multiple loops in dissectors, allows DoS
- CVE-2026-15164: Crash in ciscodump, allows DoS
- CVE-2026-15165: TLS ECH decryptor crash, allows DoS
- CVE-2026-15166: IEEE 802.11 dissector crash, allows DoS
- CVE-2026-15167: DBS Etherwatch parser crash, allows DoS
- CVE-2026-15168: BLF parser, allows information disclosure
- CVE-2026-15169: UMTS FP dissector crash, allows DoS
- CVE-2026-15170: Z39.50 dissector crash, allows DoS
- CVE-2026-15171: SSH dissector crash, allows DoS
- CVE-2026-15172: FMP/NOTIFY dissector crash, allows DoS
- CVE-2026-15173: pcapng file parser crash, allows DoS
- CVE-2026-15174: Catapult DCT2000 dissector crash, allows DoS
- CVE-2026-19694: TTX Logger file parser crash, allows DoS
- CVE-2026-19695: Gammu DCT3 trace file parser crash, allows DoS
- CVE-2026-19696: Ixia IxVeriWave file parser crash, allows DoS
- CVE-2026-76879: C12.22 dissector crash, allows DoS
- CVE-2026-76880: RRC dissector crash, allows DoS
- CVE-2026-76881: CMS dissector crash, allows DoS
- CVE-2026-76882: Bluetooth Attribute dissector crash, allows DoS
- CVE-2026-76883: Catapult DCT2000 parser crash, allows DoS
- CVE-2026-76884: ERF parser crash, allows DoS
- CVE-2026-76885: Tektronix K12xx parser crash, allows DoS
- CVE-2026-76886: C12.22 dissector crash, allows DoS
- CVE-2026-76887: Dissection engine crash, allows DoS
- CVE-2026-76888: RDP dissector crash, allows DoS
- CVE-2026-76889: UMTS FP dissector crash, allows DoS
- CVE-2026-76890: Crash in sharkd, allows DoS
- CVE-2026-76891: Crash in sharkd, allows DoS
- CVE-2026-76917: Bluetooth AVRCP dissector crash, allows DoS
- CVE-2026-76918: SSH dissector crash, allows DoS
- CVE-2026-76919: ESS dissector crash, allows DoS
- CVE-2026-76920: 3gpp phone log parser crash, allows DoS
- CVE-2026-76921: CMS dissector crash, allows DoS
- CVE-2026-76922: Bluetooth BR/EDR FHS dissector crash, allows DoS
- CVE-2026-76923: Bluetooth HFP dissector crash, allows DoS
- CVE-2026-76924: Kerberos dissector crash, allows DoS
- CVE-2026-76926: BUSMASTER parser abnormal exit, allows DoS
- CVE-2026-76927: H.245 dissector crash, allows DoS
- CVE-2026-76928: X.509IF dissector crash, allows DoS
- CVE-2026-76929: Pcapng parser crash, allows DoS
- CVE-2026-95386: TTL file parser infinite loop, allows DoS
- CVE-2026-95387: SPDY dissector crash, allows DoS
- CVE-2026-95388: Crash in sharkd, allows DoS
- CVE-2026-95389: SCTP dissector crash, allows DoS
- CVE-2026-95390: PEAK CAN TRC file parser crash, allows DoS
- CVE-2026-95391: ZigBee ZCL protocol dissector crash, allows DoS
- CVE-2026-95392: MBIM dissector crash, allows DoS
- CVE-2026-95393: CSN.1 dissector crash, allows DoS
- CVE-2026-95394: MNM parser large loop, allows DoS
- CVE-2026-95395: IEEE C37.118 dissector memory leak, allows DoS
- CVE-2026-96415: Catapult DCT2000 dissector crash, allows DoS
- CVE-2026-96416: IEEE 802.11 dissector crash, allows DoS
- CVE-2026-96417: RF4CE dissector crash, allows DoS
- CVE-2026-96418: TIFF dissector infinite loop, allows DoS
- CVE-2026-96419: Profile import crash, possible code execution
- CVE-2026-96420: Toshiba parser crash, allows DoS
- CVE-2026-96421: USB HID dissector memory leak, allows DoS
- CVE-2026-96422: Frame metadissector crash, allows DoS
- CVE-2026-96423: X11 dissector crash, allows DoS
* d/libwireshark19.symbols: Update symbols file
Checksums-Sha1:
931363145eba53bc8cc0b844e18395d2e0e0cdb7 3698 wireshark_4.6.9-1.dsc
4c2ba4500ad91708080e77e738b601046aed9ece 61166804 wireshark_4.6.9.orig.tar.bz2
386144ff4abb9f7847c5eb3bb3267d4c5dade890 91640 wireshark_4.6.9-1.debian.tar.xz
62316a60766fef5deb0c6fc9d692db2add409739 26464 wireshark_4.6.9-1_amd64.buildinfo
Checksums-Sha256:
420344d5e08fb30427f0b805d809bfcda33f4d5ba3365a1346eb78c7ddf156b1 3698 wireshark_4.6.9-1.dsc
ac98b261c824930442f9e755011a96b78e58bd09dc6a33507b1819f44222f262 61166804 wireshark_4.6.9.orig.tar.bz2
03d12852d31f58c652bc84c60bf5cf3a95d02d5d66771372b8792eb522893e1d 91640 wireshark_4.6.9-1.debian.tar.xz
f0db61cc4042549a441a16693196b456384415479f64a8d0f61cb097b28f4274 26464 wireshark_4.6.9-1_amd64.buildinfo
Files:
9bf0b8676a86c6e31d6deaae5807b1d9 3698 net optional wireshark_4.6.9-1.dsc
78cbfb1fbc0e55fb38fc86a45afa0114 61166804 net optional wireshark_4.6.9.orig.tar.bz2
0b1057b655582203234060876632f5a5 91640 net optional wireshark_4.6.9-1.debian.tar.xz
9bdbef9d576927a0546d2b45d0c311c4 26464 net optional wireshark_4.6.9-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEcRD/fHLtdypUR2KKShyoWjj77loFAmrGoNoACgkQShyoWjj7
7loT2xAAhJ8ojkejsXUuEL+E2rGCQv4s1d6vox4yq2ZXqVQLrW0FiIUxHvIqK80y
EZioH0Ewo1WUvEsfk232bqUuMGeNlMn1FfcRILG845AsoUg+9dT1A0wP5h6/jjQM
Lq9AjtP/jTfMZ8RDJmpheaDRa3JusbgDxTqx7ahZGzNasu75eq8hFgZHyfHrBKRB
/eAx6FE3nncPpAAPi3KpRK9TrNkeuWKG9WOE6DAv2ST97/Sl91qQTU5QRcN9u42i
jIItOBhRjyUDTdtjP6Hr8/1iaRpFKYbmSgYlNKu5b1M3hORtVb6wgGO8pE4Y0KDx
v2CbEBf7wMWcVGXbGeaeeSywzPpi+mTvMYf+6R14UWrmOIzi0mtycE8M6dQV/PG3
kwKVkhEkDGkGe5OB9jOH88Uqx0JQNYdjR5CQ9K4hsxZZyMi5j/nBsSkXReklt5fw
k4iUdasjd0pZL5cM5wotrSo5/JPJ93meHDZNSpjyJvg6+KrbeC4ePr5lVfJ2gbKp
Jsi0xGUrpQlDg14gkeWkEbHcuGKzP0wUzMheReoh2SxAI+eQv/EobYhRJlQcnmLI
oFhUkmXZYtz9/3Y2eY7gMGejhJHgwiC8U5ADy7M2Hte79Mp4w6E/+YIbcjAXrnTp
rkKZZBmaqozF3b3esX4EEfn1P6TTA4wVEf/2Pw03OaG8O2fEEmE=
=VMAv
-----END PGP SIGNATURE-----