Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

SUSE: wireshark Moderate DoS Issue Fix Advisory 2025:4440-1

suse
Calendar Grey December 17, 2025
Dist Suse Esm H88
Security update for wireshark fixes two vulnerabilities and improves safety on SUSE systems. Act promptly.
An update that solves two vulnerabilities can now be installed.

Summary

## This update for wireshark fixes the following issues: * CVE-2025-13499: Fixed Kafka dissector crash due to malformed packet (bsc#1254108). * CVE-2025-13946: Fixed MEGACO dissector infinite loop that allows denial of service (bsc#1254472). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4440=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-4440=1 openSUSE-SLE-15.6-2025-4440=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4440=1 ## Package List:

References

* bsc#1254108

* bsc#1254472

Cross-

* CVE-2025-13499

* CVE-2025-13946

CVSS scores:

* CVE-2025-13499 ( SUSE ): 6.9

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-13499 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

* CVE-2025-13499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2025-13499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-13946 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-13946 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7

* Desktop Applications Module 15-SP7

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP7

* SUSE Linux Enterprise Server 15 SP7

Announcement ID: SUSE-SU-2025:4440-1
Release Date: 2025-12-17T15:44:46Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here