Description
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Published: 2026-04-30
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled recursion bug exists in the BT‑DHT protocol dissector of Wireshark. When the dissector processes a malicious packet, the recursion never terminates, causing the application to exhaust its resources and crash. The weakness is classified as CWE‑617 and CWE‑674. The result is a denial of service in the Wireshark process, potentially stopping analysis of network traffic and exposing the host to further attacks. The CVE description explicitly states that the issue results in a crash, indicating that an attacker could achieve a local denial of service by influencing the packet data that Wireshark processes.

Affected Systems

The vulnerability affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Users running any of these releases on the Wireshark Foundation build must be aware that they are exposed to the recursion bug until an updated version is installed.

Risk and Exploitability

The CVSS score of 5.5 places the vulnerability in the medium severity range. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local or remote if the victim opens a malicious capture file. An attacker would need to supply or inject a crafted BT‑DHT packet to force the dissector to recurse until the application crashes. Since Wireshark is an analysis tool, the impact is confined to the host running the software, but denial of service can disrupt network monitoring and logging.

Generated by OpenCVE AI on May 4, 2026 at 13:52 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.5 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.5 or later; if using the 4.4 series, upgrade to 4.4.15 or newer. This patch removes the uncontrolled recursion path in the BT‑DHT dissector.
  • If an upgrade is not possible immediately, configure Wireshark to disable the BT‑DHT dissector or suppress processing of BT‑DHT packets, reducing the likelihood of exploitation.
  • Apply firewall rules to block BT‑DHT traffic on the network, preventing malicious packets from reaching Wireshark instances.
  • Monitor system logs for unexpected Wireshark crashes and review capture file sources for suspicious activity.

Generated by OpenCVE AI on May 4, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6249-1 wireshark security update
History

Mon, 04 May 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-617
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 01 May 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

Thu, 30 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Thu, 30 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
Description BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Title Uncontrolled Recursion in Wireshark
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-04-30T12:51:52.698Z

Reserved: 2026-04-02T06:33:41.677Z

Link: CVE-2026-5408

cve-icon Vulnrichment

Updated: 2026-04-30T12:51:45.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-30T07:16:38.263

Modified: 2026-05-01T19:25:38.157

Link: CVE-2026-5408

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-30T05:40:59Z

Links: CVE-2026-5408 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-04T14:00:20Z

Weaknesses