Impact
Wireshark’s C12.22 protocol dissector contains a stack-based buffer overflow that can be triggered when parsing certain malformed input, causing the application to crash. The vulnerability is classified as CWE-121 and results in denial of service by terminating the Wireshark session.
Affected Systems
Wireshark Foundation’s Wireshark software is affected in versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. The vendor recommends upgrading to 4.6.8 or later to remove the flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in KEV. While the official description does not specify the attacker’s required environment, it is reasonable to infer that the exploit requires feeding a crafted capture file to the dissector, which suggests a local or user‑initiated attack vector rather than a remote network‑based one.
OpenCVE Enrichment