CVE-2025-9817: NULL Pointer Dereference in Wireshark
Published Sep 3, 2025
·Updated
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
Affected Software
3 affected components
Wireshark Wireshark>=4.4.0<=4.4.8
Wireshark Wireshark>=4.4.0<=4.4.8
Wireshark Wireshark=4.4.9-rc0
Remediation
Information
Upgrade to version 4.4.9 or above
Event History
Sep 3, 2025
CVE Published
via MITRE·07:38 AM
Data Sourced
via MITRE·07:38 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via Red Hat·08:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-9817?
CVE-2025-9817 has a severity level that indicates it can lead to denial of service due to a crash in the SSH dissector.
2
How do I fix CVE-2025-9817?
To fix CVE-2025-9817, update Wireshark to a version later than 4.4.8.
3
What versions of Wireshark are affected by CVE-2025-9817?
CVE-2025-9817 affects Wireshark versions 4.4.0 through 4.4.8.
4
What type of vulnerability is CVE-2025-9817?
CVE-2025-9817 is a denial of service vulnerability caused by a crash in the SSH dissector.
5
Can CVE-2025-9817 be exploited remotely?
Yes, CVE-2025-9817 can potentially be exploited remotely, leading to a denial of service.