Home

Description

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

PUBLISHED Reserved 2025-12-03 | Published 2025-12-03 | Updated 2025-12-03 | Assigner GitLab




MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-1325: Improperly Controlled Sequential Memory Allocation

Product status

Default status
unaffected

4.6.0 (semver) before 4.6.1
affected

Credits

Sébastien Féry finder

References

www.wireshark.org/security/wnpa-sec-2025-07.html

gitlab.com/wireshark/wireshark/-/issues/20860 (GitLab Issue #20860) issue-tracking permissions-required

cve.org (CVE-2025-13945)

nvd.nist.gov (CVE-2025-13945)