Description
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Problem types
CWE-1325: Improperly Controlled Sequential Memory Allocation
Product status
4.6.0 (semver) before 4.6.5
4.4.0 (semver) before 4.4.15
Credits
Brendan Coles
References
www.wireshark.org/security/wnpa-sec-2026-26.html
gitlab.com/wireshark/wireshark/-/issues/21097 (GitLab Issue #21097)
gitlab.com/wireshark/wireshark/-/issues/21098 (GitLab Issue #21098)