An update that solves three vulnerabilities can now be installed.. # Security update for wireshark Announcement ID: SUSE-SU-2026:0237-1 Release Date: 2026-01-22T12:26:16Z Rating: moderate References: * bsc#1256734 * bsc#1256736 * bsc#1256739 Cross-References: * CVE-2026-0959 * CVE-2026-0960 * CVE-2026-0962 CVSS scores: * CVE-2026-0959 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0959 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0959 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0959 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0960 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0960 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0960 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0960 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0962 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-0962 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0962 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-0962 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues: * CVE-2026-0959: IEEE 802.11 dissector crash (bsc#1256734). * CVE-2026-0960: HTTP3 dissector infinite loop (bsc#1256736). * CVE-2026-0962: SOME/IP-SD dissector crash (bsc#1256739). ## Patch Instructions: To install this SUSE update use theSUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-237=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-237=1 openSUSE-SLE-15.6-2026-237=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-237=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wireshark-devel-4.2.14-150600.18.35.1 * wireshark-debuginfo-4.2.14-150600.18.35.1 * wireshark-ui-qt-debuginfo-4.2.14-150600.18.35.1 * wireshark-debugsource-4.2.14-150600.18.35.1 * wireshark-ui-qt-4.2.14-150600.18.35.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * wireshark-devel-4.2.14-150600.18.35.1 * libwireshark17-debuginfo-4.2.14-150600.18.35.1 * wireshark-debuginfo-4.2.14-150600.18.35.1 * libwiretap14-debuginfo-4.2.14-150600.18.35.1 * libwiretap14-4.2.14-150600.18.35.1 * wireshark-ui-qt-debuginfo-4.2.14-150600.18.35.1 * wireshark-debugsource-4.2.14-150600.18.35.1 * libwsutil15-debuginfo-4.2.14-150600.18.35.1 * libwireshark17-4.2.14-150600.18.35.1 * wireshark-4.2.14-150600.18.35.1 * wireshark-ui-qt-4.2.14-150600.18.35.1 * libwsutil15-4.2.14-150600.18.35.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libwireshark17-debuginfo-4.2.14-150600.18.35.1 * wireshark-debuginfo-4.2.14-150600.18.35.1 * libwiretap14-debuginfo-4.2.14-150600.18.35.1 * libwiretap14-4.2.14-150600.18.35.1 * wireshark-debugsource-4.2.14-150600.18.35.1 * libwsutil15-debuginfo-4.2.14-150600.18.35.1 * libwireshark17-4.2.14-150600.18.35.1 * wireshark-4.2.14-150600.18.35.1 * libwsutil15-4.2.14-150600.18.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0959.html * https://www.suse.com/security/cve/CVE-2026-0960.html *https://www.suse.com/security/cve/CVE-2026-0962.html * https://bugzilla.suse.com/show_bug.cgi?id=1256734 * https://bugzilla.suse.com/show_bug.cgi?id=1256736 * https://bugzilla.suse.com/show_bug.cgi?id=1256739 . Update for openSUSE addresses multiple wireshark flaws enhancing overall security for users.. openSUSE security update, wireshark vulnerabilities, moderate security threat, software patching. . LinuxSecurity.com Team
The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file. . MGASA-2024-0045 - Updated wireshark packages fix security vulnerabilities Publication date: 20 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0045.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-5371, CVE-2023-6174, CVE-2023-6175, CVE-2024-0208 The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file. (CVE-2024-0208) References: - https://bugs.mageia.org/show_bug.cgi?id=32835 - https://lists.fedoraproject.org/archives/list/
Kafka dissector infinite loop (CVE-2021-4190). RTMPT dissector infinite loop (wnpa-sec-2022-01). Large loops in multiple dissectors (wnpa-sec-2022-02). . MGASA-2022-0068 - Updated wireshark packages fix security vulnerability Publication date: 18 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0068.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-4190 Kafka dissector infinite loop (CVE-2021-4190). RTMPT dissector infinite loop (wnpa-sec-2022-01). Large loops in multiple dissectors (wnpa-sec-2022-02). PVFS dissector crash (wnpa-sec-2022-03). CSN.1 dissector crash (wnpa-sec-2022-04). CMS dissector crash (wnpa-sec-2022-05). References: - https://bugs.mageia.org/show_bug.cgi?id=30035 - https://www.wireshark.org/security/wnpa-sec-2021-22 - https://www.wireshark.org/security/wnpa-sec-2022-01 - https://www.wireshark.org/security/wnpa-sec-2022-02 - https://www.wireshark.org/security/wnpa-sec-2022-03 - https://www.wireshark.org/security/wnpa-sec-2022-04 - https://www.wireshark.org/security/wnpa-sec-2022-05 - https://www.wireshark.org/docs/relnotes/wireshark-3.4.12.html - https://www.wireshark.org/news/20220210.html - https://www.cve.org/CVERecord?id=CVE-2021-4190 SRPMS: - 8/core/wireshark-3.4.12-1.mga8 . Mageia 2022-0069 refreshes firefox bundles to address several significant vulnerabilities affecting numerous components.. wireshark update, security advisory, mageia security, wireshark vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
The MS-WSP dissector could consume excessive amounts of memory (CVE-2021-22207). References: - https://bugs.mageia.org/show_bug.cgi?id=28915 . MGASA-2021-0222 - Updated wireshark packages fix a security vulnerability Publication date: 27 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0222.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-22207 The MS-WSP dissector could consume excessive amounts of memory (CVE-2021-22207). References: - https://bugs.mageia.org/show_bug.cgi?id=28915 - https://www.wireshark.org/security/wnpa-sec-2021-04 - https://www.wireshark.org/docs/relnotes/wireshark-3.4.5.html - https://www.wireshark.org/news/20210421.html - https://www.cve.org/CVERecord?id=CVE-2021-22207 SRPMS: - 8/core/wireshark-3.4.5-1.mga8 . Revised Wireshark installations resolve a memory vulnerability present in Mageia's version released on May 27, 2021.. Mageia Wireshark Update, Memory Security Check, Wireshark Memory Consumption. . LinuxSecurity.com Team
New version 3.2.4, enabled build with androiddump.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-4f5588cf97 2020-05-30 01:53:14.472018 --------------------------------------------------------------------------------Name : wireshark Product : Fedora 32 Version : 3.2.4 Release : 1.fc32 URL : https://www.wireshark.org/ Summary : Network traffic analyzer Description : Wireshark allows you to examine protocol data stored in files or as it is captured from wired or wireless (WiFi or Bluetooth) networks, USB devices, and many other sources. It supports dozens of protocol capture file formats and understands more than a thousand protocols. It has many powerful features including a rich display filter language and the ability to reassemble multiple protocol packets in order to, for example, view a complete TCP stream, save the contents of a file which was transferred over HTTP or CIFS, or play back an RTP audio stream. --------------------------------------------------------------------------------Update Information: New version 3.2.4, enabled build with androiddump. --------------------------------------------------------------------------------ChangeLog: * Fri May 22 2020 Michal Ruprich - 1:3.2.4-1 - New version 3.2.4 - Enabling build with androiddump (rhbz#1834367) --------------------------------------------------------------------------------References: [ 1 ] Bug #1839874 - CVE-2020-13164 wireshark: NFS dissector crash (wnpa-sec-2020-08) https://bugzilla.redhat.com/show_bug.cgi?id=1839874 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-4f5588cf97' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated wireshark packages fix security vulnerability: The Gryphon dissector could go into an infinite loop. For other fixes in this update, see the referenced releasenotes. . MGASA-2019-0282 - Updated wireguard packages fix security vulnerability Publication date: 15 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0282.html Type: security Affected Mageia releases: 7 Updated wireshark packages fix security vulnerability: The Gryphon dissector could go into an infinite loop. For other fixes in this update, see the referenced releasenotes. References: - https://bugs.mageia.org/show_bug.cgi?id=25436 - https://www.wireshark.org/security/wnpa-sec-2019-21 - https://www.wireshark.org/docs/relnotes/wireshark-3.0.4.html - https://www.wireshark.org/news/20190911.html SRPMS: - 7/core/wireshark-3.0.4-1.mga7 . Recent wireguard updates have resolved a critical security flaw associated with an endless looping error in the Gryphon parser. Find additional information here.. Mageia Security Update, Wireshark Patch, Gryphon Dissector Fix. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for wireshark ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1965-1 Rating: moderate References: #1141980 Cross-References: CVE-2019-13619 Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for wireshark to version 2.4.16 fixes the following issues: Security issue fixed: - CVE-2019-13619: ASN.1 BER and related dissectors crash (bsc#1141980). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1965=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1965=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libwireshark9-2.4.16-lp151.2.6.1 libwireshark9-debuginfo-2.4.16-lp151.2.6.1 libwiretap7-2.4.16-lp151.2.6.1 libwiretap7-debuginfo-2.4.16-lp151.2.6.1 libwscodecs1-2.4.16-lp151.2.6.1 libwscodecs1-debuginfo-2.4.16-lp151.2.6.1 libwsutil8-2.4.16-lp151.2.6.1 libwsutil8-debuginfo-2.4.16-lp151.2.6.1 wireshark-2.4.16-lp151.2.6.1 wireshark-debuginfo-2.4.16-lp151.2.6.1 wireshark-debugsource-2.4.16-lp151.2.6.1 wireshark-devel-2.4.16-lp151.2.6.1 wireshark-ui-qt-2.4.16-lp151.2.6.1 wireshark-ui-qt-debuginfo-2.4.16-lp151.2.6.1 - openSUSE Leap 15.0 (i586 x86_64): libwireshark9-2.4.16-lp150.2.32.1 libwireshark9-debuginfo-2.4.16-lp150.2.32.1 libwiretap7-2.4.16-lp150.2.32.1 libwiretap7-debuginfo-2.4.16-lp150.2.32.1 libwscodecs1-2.4.16-lp150.2.32.1 libwscodecs1-debuginfo-2.4.16-lp150.2.32.1 libwsutil8-2.4.16-lp150.2.32.1 libwsutil8-debuginfo-2.4.16-lp150.2.32.1 wireshark-2.4.16-lp150.2.32.1 wireshark-debuginfo-2.4.16-lp150.2.32.1 wireshark-debugsource-2.4.16-lp150.2.32.1 wireshark-devel-2.4.16-lp150.2.32.1 wireshark-ui-qt-2.4.16-lp150.2.32.1 wireshark-ui-qt-debuginfo-2.4.16-lp150.2.32.1 References: https://www.suse.com/security/cve/CVE-2019-13619.html https://bugzilla.suse.com/1141980 -- . A new security patch for openSUSE resolves an ASN.1 parser flaw in Wireshark that could lead to system instability issues.. openSUSE wireshark security update ASN.1 crash. . LinuxSecurity.com Team
An update that fixes 6 vulnerabilities is now available.. openSUSE Security Update: Security update for wireshark ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:4307-1 Rating: moderate References: #1117740 Cross-References: CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for wireshark fixes the following issues: Update to Wireshark 2.4.11 (bsc#1117740). Security issues fixed: - CVE-2018-19625: The Wireshark dissection engine could crash (wnpa-sec-2018-51) - CVE-2018-19626: The DCOM dissector could crash (wnpa-sec-2018-52) - CVE-2018-19623: The LBMPDM dissector could crash (wnpa-sec-2018-53) - CVE-2018-19622: The MMSE dissector could go into an infinite loop (wnpa-sec-2018-54) - CVE-2018-19627: The IxVeriWave file parser could crash (wnpa-sec-2018-55) - CVE-2018-19624: The PVFS dissector could crash (wnpa-sec-2018-56) Further bug fixes and updated protocol support as listed in: - https://www.wireshark.org/docs/relnotes/wireshark-2.4.11.html This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1620=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libwireshark9-2.4.11-lp150.2.16.1 libwireshark9-debuginfo-2.4.11-lp150.2.16.1 libwiretap7-2.4.11-lp150.2.16.1 libwiretap7-debuginfo-2.4.11-lp150.2.16.1 libwscodecs1-2.4.11-lp150.2.16.1 libwscodecs1-debuginfo-2.4.11-lp150.2.16.1 libwsutil8-2.4.11-lp150.2.16.1 libwsutil8-debuginfo-2.4.11-lp150.2.16.1 wireshark-2.4.11-lp150.2.16.1 wireshark-debuginfo-2.4.11-lp150.2.16.1 wireshark-debugsource-2.4.11-lp150.2.16.1 wireshark-devel-2.4.11-lp150.2.16.1 wireshark-ui-qt-2.4.11-lp150.2.16.1 wireshark-ui-qt-debuginfo-2.4.11-lp150.2.16.1 References: https://www.suse.com/security/cve/CVE-2018-19622.html https://www.suse.com/security/cve/CVE-2018-19623.html https://www.suse.com/security/cve/CVE-2018-19624.html https://www.suse.com/security/cve/CVE-2018-19625.html https://www.suse.com/security/cve/CVE-2018-19626.html https://www.suse.com/security/cve/CVE-2018-19627.html https://bugzilla.suse.com/1117740 -- . openSUSE Security Update: Security update for wireshark Announcement ID: openSUSE-SU-2018:4307-1 Rat. update, security, fixes, vulnerabilities, opensuse. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.