Description
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Published: 2026-04-30
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a logic error in the SANE protocol dissector that causes an infinite loop while parsing packets, consuming all CPU resources and preventing Wireshark from continuing to process traffic, effectively rendering the application unresponsive and leading to a denial of service for the local user. This is an example of CWE‑835, where a program never terminates or terminates badly. Affected systems include Wireshark Foundation’s Wireshark application in the 4.6 series from version 4.6.0 through 4.6.4 and in the 4.4 series from version 4.4.0 through 4.4.14; all installations using the default SANE dissector during packet capture are impacted. No specific platform or operating system constraints are stated in the data.

Affected Systems

Wireshark Foundation Wireshark application versions 4.6.0‑4.6.4 and 4.4.0‑4.4.14 that include the default SANE dissector.

Risk and Exploitability

With a CVSS score of 5.5, the vulnerability poses a moderate risk of service disruption; the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The infinite loop can be triggered by sending specially crafted SANE packets to a running Wireshark instance, making the likely attack vector remote. An environment where Wireshark is exposed to untrusted networks or users is more susceptible, and no additional prerequisites are disclosed, so a simple packet injection could suffice. Overall, the risk is moderate but not negligible; systems that rely on continuous packet capture should mitigate promptly to prevent accidental denial of service from malformed traffic.

Generated by OpenCVE AI on May 2, 2026 at 00:23 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.5 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.5 or later to remove the infinite‑loop bug.
  • If an upgrade cannot be performed immediately, disable the SANE protocol dissector in the capture options to avoid parsing problematic packets.
  • Monitor capture sessions for unresponsive or crashed instances and consider restarting Wireshark if a denial of service occurs.

Generated by OpenCVE AI on May 2, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6249-1 wireshark security update
History

Mon, 04 May 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 01 May 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

Thu, 30 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Thu, 30 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
Description SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Title Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-04-30T13:04:58.095Z

Reserved: 2026-04-17T15:06:07.694Z

Link: CVE-2026-6531

cve-icon Vulnrichment

Updated: 2026-04-30T13:04:07.449Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-30T07:16:40.373

Modified: 2026-05-01T18:16:54.217

Link: CVE-2026-6531

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-30T05:36:29Z

Links: CVE-2026-6531 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T00:30:16Z

Weaknesses