CVE-2026-7375 - Vulnerability Analysis
MediumCVSS: 5.5Last Updated: May 1, 2026
Wireshark - Denial of Service
Published: April 30, 2026Updated: May 1, 2026PoC Available
Overview
Wireshark 4.4.0 to 4.4.14 and 4.6.0 to 4.6.4 contain a denial of service caused by an infinite loop in the UDS protocol dissector, letting remote attackers cause application crash, exploit requires crafted network packets.
Severity & Score
Severity: Medium
CVSS Score: 5.5
Impact
Attackers can cause Wireshark to enter an infinite loop, leading to denial of service and application crash.
Mitigation
Update to a version later than 4.6.4 or 4.4.14.
References
Related Resources
Details
- CVE ID
- CVE-2026-7375
- Severity
- Medium
- CVSS Score
- 5.5
- Type
- denial_of_service
- Status
- confirmed
CWE
- CWE-835
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H