CVE-2018-18226: High severity wireshark vulnerability
Published Oct 12, 2018
·Updated
In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.
Affected Software
3 affected componentsFixes available
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u73.4.10-0+deb11u14.0.6-1~deb12u14.0.10-1
Wireshark Wireshark>=2.6.0<=2.6.3
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Oct 12, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18226?
CVE-2018-18226 has a severity rating that indicates it can lead to excessive memory consumption in Wireshark.
2
How do I fix CVE-2018-18226?
To fix CVE-2018-18226, update Wireshark to versions 2.6.20-0+deb10u4, 2.6.20-0+deb10u7, 3.4.10-0+deb11u1, 4.0.6-1~deb12u1, or 4.0.10-1.
3
Which versions of Wireshark are affected by CVE-2018-18226?
Wireshark versions 2.6.0 to 2.6.3 are affected by CVE-2018-18226.
4
Is CVE-2018-18226 present in Debian GNU/Linux?
Yes, CVE-2018-18226 is present in Debian GNU/Linux 9.0 running affected versions of Wireshark.
5
What component of Wireshark is impacted by CVE-2018-18226?
The Steam IHS Discovery dissector in Wireshark is impacted by CVE-2018-18226.