Impact
A memory management flaw in Wireshark's packet capture component, sharkd, causes the application to crash when processing certain traffic. The vulnerability is identified as a use‑after‑free error (CWE‑825) and results in a denial of service attack by terminating the Wireshark process.
Affected Systems
Wireshark Foundation Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 are affected. The issue does not apply to later releases such as 4.6.8 or higher.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply or influence traffic that is processed by sharkd, which may require local or remote network access depending on how the capture service is exposed. The exploit would trigger a crash, causing a denial of service for the user or system running Wireshark.
OpenCVE Enrichment
Debian DSA