Impact
The vulnerability resides in Wireshark’s SMB2 protocol dissector and allows an attacker to trigger a crash by sending specially crafted SMB2 packets. This leads to a denial of service, affecting the availability of Wireshark as a network analysis tool. The weakness is a sequential memory allocation error, identified as CWE‑1325 and CWE‑1286.
Affected Systems
Affected products are Wireshark by the Wireshark Foundation. Versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14 are impacted. All installations of these versions running the SMB2 dissector are vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in CISA KEV. The attack vector is inferred; an attacker can supply a malicious capture file or inject crafted SMB2 traffic during a live capture, leading to a crash. No privileged access is required beyond the ability to run or open Wireshark, so the attack is likely local or remote depending on the environment.
OpenCVE Enrichment
Debian DSA