Impact
The vulnerability stems from a use‑after‑free bug in Wireshark's CMS protocol dissector, causing the application to crash when processing certain CMS packets. This leads to denial of service of the application and any dependent services that rely on Wireshark’s stability. The weakness corresponds to CWE‑416, indicating a flaw in memory management. Based on the description, it is inferred that a crafted CMS packet triggers the use‑after‑free, but explicit crash trigger details are not disclosed.
Affected Systems
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are affected. Users running these releases should identify the exact minor version they are using and plan for an update.
Risk and Exploitability
The CVSS score of 5.5 reflects medium severity; no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be through a crafted CMS packet delivered over a network or file opened by Wireshark; processing that packet triggers the crash. This local attack limits the impact to application instability rather than privilege escalation or data compromise.
OpenCVE Enrichment
Debian DSA