#1149644 wireshark: CVE-2026-95386 CVE-2026-95387 CVE-2026-95388 CVE-2026-95389 CVE-2026-95390 CVE-2026-95391 CVE-2026-95392 CVE-2026-95393 CVE-2026-95394 CVE-2026-95395 CVE-2026-96415 CVE-2026-96416 CVE-2026-96417 CVE-2026-96418 CVE-2026-96419 CVE-2026-96420 CVE-2026-96421 CVE-2026-96422 CVE-2026-96423 #1149644
- Package:
- src:wireshark
- Source:
- src:wireshark
- Submitter:
- Moritz Mühlenhoff
- Date:
- 2026-10-07 20:29:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for wireshark. We should also ship 4.4.19 via trixie-securiy, could someone of the Wireshark maintainers please prepare an update?` CVE-2026-95386[0]: | TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of | service https://www.wireshark.org/security/wnpa-sec-2026-94 https://gitlab.com/wireshark/wireshark/-/issues/21501 CVE-2026-95387[1]: | SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-97 https://gitlab.com/wireshark/wireshark/-/issues/21487 CVE-2026-95388[2]: | Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows | denial of service https://www.wireshark.org/security/wnpa-sec-2026-101 https://gitlab.com/wireshark/wireshark/-/issues/21545 CVE-2026-95389[3]: | SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-93 https://gitlab.com/wireshark/wireshark/-/issues/21481 CVE-2026-95390[4]: | PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of | service https://www.wireshark.org/security/wnpa-sec-2026-95 https://gitlab.com/wireshark/wireshark/-/issues/21503 CVE-2026-95391[5]: | ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial | of service https://www.wireshark.org/security/wnpa-sec-2026-92 https://gitlab.com/wireshark/wireshark/-/merge_requests/26096 CVE-2026-95392[6]: | MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://gitlab.com/wireshark/wireshark/-/issues/21549 https://gitlab.com/wireshark/wireshark/-/issues/21550 CVE-2026-95393[7]: | CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-99 https://gitlab.com/wireshark/wireshark/-/issues/21510 CVE-2026-95394[8]: | Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 | and 4.4.0 to 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-98 https://gitlab.com/wireshark/wireshark/-/issues/21523 CVE-2026-95395[9]: | IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 | to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-96 https://gitlab.com/wireshark/wireshark/-/issues/21492 CVE-2026-96415[10]: | Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and | 4.4.0 to 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-110 https://gitlab.com/wireshark/wireshark/-/issues/21589 CVE-2026-96416[11]: | IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to | 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-109 https://gitlab.com/wireshark/wireshark/-/issues/21564 CVE-2026-96417[12]: | RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-104 https://gitlab.com/wireshark/wireshark/-/issues/21574 CVE-2026-96418[13]: | TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to | 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-107 https://gitlab.com/wireshark/wireshark/-/issues/21565 CVE-2026-96419[14]: | Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows | denial of service and possible code execution https://www.wireshark.org/security/wnpa-sec-2026-106 https://gitlab.com/wireshark/wireshark/-/issues/21553 CVE-2026-96420[15]: | Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-105 https://gitlab.com/wireshark/wireshark/-/issues/21541 CVE-2026-96421[16]: | USB HID protocol dissector infinite loop and memory leak in 4.6.0 to | 4.6.8 and 4.4.0 to 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-103 https://gitlab.com/wireshark/wireshark/-/issues/21566 CVE-2026-96422[17]: | Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to | 4.4.18 allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-102 https://gitlab.com/wireshark/wireshark/-/issues/21525 CVE-2026-96423[18]: | X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 | allows denial of service https://www.wireshark.org/security/wnpa-sec-2026-108 https://gitlab.com/wireshark/wireshark/-/issues/21563 If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-95386 https://www.cve.org/CVERecord?id=CVE-2026-95386 [1] https://security-tracker.debian.org/tracker/CVE-2026-95387 https://www.cve.org/CVERecord?id=CVE-2026-95387 [2] https://security-tracker.debian.org/tracker/CVE-2026-95388 https://www.cve.org/CVERecord?id=CVE-2026-95388 [3] https://security-tracker.debian.org/tracker/CVE-2026-95389 https://www.cve.org/CVERecord?id=CVE-2026-95389 [4] https://security-tracker.debian.org/tracker/CVE-2026-95390 https://www.cve.org/CVERecord?id=CVE-2026-95390 [5] https://security-tracker.debian.org/tracker/CVE-2026-95391 https://www.cve.org/CVERecord?id=CVE-2026-95391 [6] https://security-tracker.debian.org/tracker/CVE-2026-95392 https://www.cve.org/CVERecord?id=CVE-2026-95392 [7] https://security-tracker.debian.org/tracker/CVE-2026-95393 https://www.cve.org/CVERecord?id=CVE-2026-95393 [8] https://security-tracker.debian.org/tracker/CVE-2026-95394 https://www.cve.org/CVERecord?id=CVE-2026-95394 [9] https://security-tracker.debian.org/tracker/CVE-2026-95395 https://www.cve.org/CVERecord?id=CVE-2026-95395 [10] https://security-tracker.debian.org/tracker/CVE-2026-96415 https://www.cve.org/CVERecord?id=CVE-2026-96415 [11] https://security-tracker.debian.org/tracker/CVE-2026-96416 https://www.cve.org/CVERecord?id=CVE-2026-96416 [12] https://security-tracker.debian.org/tracker/CVE-2026-96417 https://www.cve.org/CVERecord?id=CVE-2026-96417 [13] https://security-tracker.debian.org/tracker/CVE-2026-96418 https://www.cve.org/CVERecord?id=CVE-2026-96418 [14] https://security-tracker.debian.org/tracker/CVE-2026-96419 https://www.cve.org/CVERecord?id=CVE-2026-96419 [15] https://security-tracker.debian.org/tracker/CVE-2026-96420 https://www.cve.org/CVERecord?id=CVE-2026-96420 [16] https://security-tracker.debian.org/tracker/CVE-2026-96421 https://www.cve.org/CVERecord?id=CVE-2026-96421 [17] https://security-tracker.debian.org/tracker/CVE-2026-96422 https://www.cve.org/CVERecord?id=CVE-2026-96422 [18] https://security-tracker.debian.org/tracker/CVE-2026-96423 https://www.cve.org/CVERecord?id=CVE-2026-96423 Please adjust the affected versions in the BTS as needed.
We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149644@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <polkorny@debian.org> (supplier of updated wireshark package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 23:53:49 -0300
Source: wireshark
Architecture: source
Version: 4.6.9-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Matheus Polkorny <polkorny@debian.org>
Closes: 1142268 1144924 1149644
Changes:
wireshark (4.6.9-1) unstable; urgency=medium
.
* Team upload.
* New upstream release (Closes: #1142268, #1144924, #1149644)
- CVE-2026-15163: Multiple loops in dissectors, allows DoS
- CVE-2026-15164: Crash in ciscodump, allows DoS
- CVE-2026-15165: TLS ECH decryptor crash, allows DoS
- CVE-2026-15166: IEEE 802.11 dissector crash, allows DoS
- CVE-2026-15167: DBS Etherwatch parser crash, allows DoS
- CVE-2026-15168: BLF parser, allows information disclosure
- CVE-2026-15169: UMTS FP dissector crash, allows DoS
- CVE-2026-15170: Z39.50 dissector crash, allows DoS
- CVE-2026-15171: SSH dissector crash, allows DoS
- CVE-2026-15172: FMP/NOTIFY dissector crash, allows DoS
- CVE-2026-15173: pcapng file parser crash, allows DoS
- CVE-2026-15174: Catapult DCT2000 dissector crash, allows DoS
- CVE-2026-19694: TTX Logger file parser crash, allows DoS
- CVE-2026-19695: Gammu DCT3 trace file parser crash, allows DoS
- CVE-2026-19696: Ixia IxVeriWave file parser crash, allows DoS
- CVE-2026-76879: C12.22 dissector crash, allows DoS
- CVE-2026-76880: RRC dissector crash, allows DoS
- CVE-2026-76881: CMS dissector crash, allows DoS
- CVE-2026-76882: Bluetooth Attribute dissector crash, allows DoS
- CVE-2026-76883: Catapult DCT2000 parser crash, allows DoS
- CVE-2026-76884: ERF parser crash, allows DoS
- CVE-2026-76885: Tektronix K12xx parser crash, allows DoS
- CVE-2026-76886: C12.22 dissector crash, allows DoS
- CVE-2026-76887: Dissection engine crash, allows DoS
- CVE-2026-76888: RDP dissector crash, allows DoS
- CVE-2026-76889: UMTS FP dissector crash, allows DoS
- CVE-2026-76890: Crash in sharkd, allows DoS
- CVE-2026-76891: Crash in sharkd, allows DoS
- CVE-2026-76917: Bluetooth AVRCP dissector crash, allows DoS
- CVE-2026-76918: SSH dissector crash, allows DoS
- CVE-2026-76919: ESS dissector crash, allows DoS
- CVE-2026-76920: 3gpp phone log parser crash, allows DoS
- CVE-2026-76921: CMS dissector crash, allows DoS
- CVE-2026-76922: Bluetooth BR/EDR FHS dissector crash, allows DoS
- CVE-2026-76923: Bluetooth HFP dissector crash, allows DoS
- CVE-2026-76924: Kerberos dissector crash, allows DoS
- CVE-2026-76926: BUSMASTER parser abnormal exit, allows DoS
- CVE-2026-76927: H.245 dissector crash, allows DoS
- CVE-2026-76928: X.509IF dissector crash, allows DoS
- CVE-2026-76929: Pcapng parser crash, allows DoS
- CVE-2026-95386: TTL file parser infinite loop, allows DoS
- CVE-2026-95387: SPDY dissector crash, allows DoS
- CVE-2026-95388: Crash in sharkd, allows DoS
- CVE-2026-95389: SCTP dissector crash, allows DoS
- CVE-2026-95390: PEAK CAN TRC file parser crash, allows DoS
- CVE-2026-95391: ZigBee ZCL protocol dissector crash, allows DoS
- CVE-2026-95392: MBIM dissector crash, allows DoS
- CVE-2026-95393: CSN.1 dissector crash, allows DoS
- CVE-2026-95394: MNM parser large loop, allows DoS
- CVE-2026-95395: IEEE C37.118 dissector memory leak, allows DoS
- CVE-2026-96415: Catapult DCT2000 dissector crash, allows DoS
- CVE-2026-96416: IEEE 802.11 dissector crash, allows DoS
- CVE-2026-96417: RF4CE dissector crash, allows DoS
- CVE-2026-96418: TIFF dissector infinite loop, allows DoS
- CVE-2026-96419: Profile import crash, possible code execution
- CVE-2026-96420: Toshiba parser crash, allows DoS
- CVE-2026-96421: USB HID dissector memory leak, allows DoS
- CVE-2026-96422: Frame metadissector crash, allows DoS
- CVE-2026-96423: X11 dissector crash, allows DoS
* d/libwireshark19.symbols: Update symbols file
Checksums-Sha1:
931363145eba53bc8cc0b844e18395d2e0e0cdb7 3698 wireshark_4.6.9-1.dsc
4c2ba4500ad91708080e77e738b601046aed9ece 61166804 wireshark_4.6.9.orig.tar.bz2
386144ff4abb9f7847c5eb3bb3267d4c5dade890 91640 wireshark_4.6.9-1.debian.tar.xz
62316a60766fef5deb0c6fc9d692db2add409739 26464 wireshark_4.6.9-1_amd64.buildinfo
Checksums-Sha256:
420344d5e08fb30427f0b805d809bfcda33f4d5ba3365a1346eb78c7ddf156b1 3698 wireshark_4.6.9-1.dsc
ac98b261c824930442f9e755011a96b78e58bd09dc6a33507b1819f44222f262 61166804 wireshark_4.6.9.orig.tar.bz2
03d12852d31f58c652bc84c60bf5cf3a95d02d5d66771372b8792eb522893e1d 91640 wireshark_4.6.9-1.debian.tar.xz
f0db61cc4042549a441a16693196b456384415479f64a8d0f61cb097b28f4274 26464 wireshark_4.6.9-1_amd64.buildinfo
Files:
9bf0b8676a86c6e31d6deaae5807b1d9 3698 net optional wireshark_4.6.9-1.dsc
78cbfb1fbc0e55fb38fc86a45afa0114 61166804 net optional wireshark_4.6.9.orig.tar.bz2
0b1057b655582203234060876632f5a5 91640 net optional wireshark_4.6.9-1.debian.tar.xz
9bdbef9d576927a0546d2b45d0c311c4 26464 net optional wireshark_4.6.9-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEcRD/fHLtdypUR2KKShyoWjj77loFAmrGoNoACgkQShyoWjj7
7loT2xAAhJ8ojkejsXUuEL+E2rGCQv4s1d6vox4yq2ZXqVQLrW0FiIUxHvIqK80y
EZioH0Ewo1WUvEsfk232bqUuMGeNlMn1FfcRILG845AsoUg+9dT1A0wP5h6/jjQM
Lq9AjtP/jTfMZ8RDJmpheaDRa3JusbgDxTqx7ahZGzNasu75eq8hFgZHyfHrBKRB
/eAx6FE3nncPpAAPi3KpRK9TrNkeuWKG9WOE6DAv2ST97/Sl91qQTU5QRcN9u42i
jIItOBhRjyUDTdtjP6Hr8/1iaRpFKYbmSgYlNKu5b1M3hORtVb6wgGO8pE4Y0KDx
v2CbEBf7wMWcVGXbGeaeeSywzPpi+mTvMYf+6R14UWrmOIzi0mtycE8M6dQV/PG3
kwKVkhEkDGkGe5OB9jOH88Uqx0JQNYdjR5CQ9K4hsxZZyMi5j/nBsSkXReklt5fw
k4iUdasjd0pZL5cM5wotrSo5/JPJ93meHDZNSpjyJvg6+KrbeC4ePr5lVfJ2gbKp
Jsi0xGUrpQlDg14gkeWkEbHcuGKzP0wUzMheReoh2SxAI+eQv/EobYhRJlQcnmLI
oFhUkmXZYtz9/3Y2eY7gMGejhJHgwiC8U5ADy7M2Hte79Mp4w6E/+YIbcjAXrnTp
rkKZZBmaqozF3b3esX4EEfn1P6TTA4wVEf/2Pw03OaG8O2fEEmE=
=VMAv
-----END PGP SIGNATURE-----