CVE-2024-9781
AppleTalk and RELOAD Framing dissector crash allows denial of
service via packet injection or crafted capture file.
CVE-2024-11596
ECMP dissector crash allows denial of service via packet injection
or crafted capture file.
CVE-2025-5601
Column handling crashes allows denial of service via packet
injection or crafted capture file.
CVE-2025-11626
MONGO dissector infinite loop allows denial of service.
CVE-2025-13499
Kafka dissector crash allows denial of service.
CVE-2025-13945
HTTP3 dissector crash allows denial of service.
CVE-2025-13946
MEGACO dissector infinite loop in allows denial of service.
CVE-2026-0960
HTTP3 protocol dissector infinite loop allows denial of service.
For Debian 11 bullseye, these problems have been fixed in version
3.4.16-0+deb11u2.
We recommend that you upgrade your wireshark packages.
For the detailed security status of wireshark please refer to
its security tracker page at:
Get the latest Linux and open source security news straight to your inbox.