PT-2024-17126 · Wireshark+4 · Wireshark+4

Ivan Nardi

·

Published

2024-10-08

·

Updated

2026-04-02

·

CVE-2024-11596

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 4.2.0 through 4.2.8 Wireshark versions 4.4.0 through 4.4.1
Description The issue allows for denial of service via packet injection or crafted capture file. It is related to the ECMP dissector crash in Wireshark.
Recommendations For Wireshark versions 4.2.0 through 4.2.8, update to a version outside of this range to resolve the issue. For Wireshark versions 4.4.0 through 4.4.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider avoiding the use of crafted capture files or packet injection to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Buffer Overflow

Buffer Over-read

Infinite Loop

Related Identifiers

ALT-PU-2025-1412
ALT-PU-2025-3923
BDU:2024-09109
BDU:2024-10175
BDU:2025-02193
CVE-2024-11596
OESA-2025-1660
OESA-2025-1661
OESA-2025-1662
OESA-2025-1663
OPENSUSE-SU-2024:14529-1
OPENSUSE-SU-2024_4142-1
SUSE-SU-2024:4142-1
SUSE-SU-2026:1169-1

Affected Products

Alt Linux
Debian
Red Os
Suse
Wireshark