Impact
The vulnerability is an expired pointer dereference in the Wireshark sharkd daemon. When triggered in versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18, the bug causes the daemon to crash, resulting in a denial‑of‑service condition. The underlying weakness is a pointer misuse classified as CWE-248 and CWE-825.
Affected Systems
Wireshark Foundation’s Wireshark product is affected; users running any release from 4.4.0 to 4.4.18 or from 4.6.0 to 4.6.7 are vulnerable and should upgrade to 4.6.8 or later.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. The EPSS score is < 1%, which suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. The likely attack vector is inferred to be either local or remote, where an attacker sends crafted traffic to the sharkd daemon. While the impact is modest, mitigating the vulnerability is advised.
OpenCVE Enrichment
Debian DSA