#1142268 wireshark: CVE-2026-15163 CVE-2026-15164 CVE-2026-15165 CVE-2026-15166 CVE-2026-15167 CVE-2026-15168 CVE-2026-15169 CVE-2026-15170 CVE-2026-15171 CVE-2026-15172 CVE-2026-15173 CVE-2026-15174

Package:
src:wireshark
Source:
src:wireshark
Submitter:
Salvatore Bonaccorso
Date:
2026-07-17 04:47:02 UTC
Severity:
normal
Tags:
#1142268#5
Date:
2026-07-17 04:45:01 UTC
From:
To:
Hi,

The following vulnerabilities were published for wireshark.

CVE-2026-15163[0]:
| Multiple protocol dissector infinite loops in Wireshark 4.6.0 to
| 4.6.6 and 4.4.0 to 4.4.16 allow denial of service


CVE-2026-15164[1]:
| Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial
| of service


CVE-2026-15165[2]:
| TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of
| service


CVE-2026-15166[3]:
| IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15167[4]:
| DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15168[5]:
| BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16
| allows possible information disclosure


CVE-2026-15169[6]:
| UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15170[7]:
| Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15171[8]:
| SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0
| to 4.4.16 allows denial of service


CVE-2026-15172[9]:
| FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
| 4.4.0 to 4.4.16 allows denial of service


CVE-2026-15173[10]:
| pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial
| of service


CVE-2026-15174[11]:
| Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to
| 4.6.6 and 4.4.0 to 4.4.16 allows denial of service


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15163
https://www.cve.org/CVERecord?id=CVE-2026-15163
[1] https://security-tracker.debian.org/tracker/CVE-2026-15164
https://www.cve.org/CVERecord?id=CVE-2026-15164
[2] https://security-tracker.debian.org/tracker/CVE-2026-15165
https://www.cve.org/CVERecord?id=CVE-2026-15165
[3] https://security-tracker.debian.org/tracker/CVE-2026-15166
https://www.cve.org/CVERecord?id=CVE-2026-15166
[4] https://security-tracker.debian.org/tracker/CVE-2026-15167
https://www.cve.org/CVERecord?id=CVE-2026-15167
[5] https://security-tracker.debian.org/tracker/CVE-2026-15168
https://www.cve.org/CVERecord?id=CVE-2026-15168
[6] https://security-tracker.debian.org/tracker/CVE-2026-15169
https://www.cve.org/CVERecord?id=CVE-2026-15169
[7] https://security-tracker.debian.org/tracker/CVE-2026-15170
https://www.cve.org/CVERecord?id=CVE-2026-15170
[8] https://security-tracker.debian.org/tracker/CVE-2026-15171
https://www.cve.org/CVERecord?id=CVE-2026-15171
[9] https://security-tracker.debian.org/tracker/CVE-2026-15172
https://www.cve.org/CVERecord?id=CVE-2026-15172
[10] https://security-tracker.debian.org/tracker/CVE-2026-15173
https://www.cve.org/CVERecord?id=CVE-2026-15173
[11] https://security-tracker.debian.org/tracker/CVE-2026-15174
https://www.cve.org/CVERecord?id=CVE-2026-15174

Regards,
Salvatore