CVE-2026-3201: Improperly Controlled Sequential Memory Allocation in Wireshark
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wiresharkto a version that resolves this vulnerability.Fixed in 4.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3201?
The severity of CVE-2026-3201 is classified as a denial of service vulnerability due to improper memory allocation in Wireshark.
How do I fix CVE-2026-3201?
To fix CVE-2026-3201, upgrade Wireshark to version 4.6.4 or later, or 4.4.14 or later.
What versions of Wireshark are affected by CVE-2026-3201?
CVE-2026-3201 affects Wireshark versions 4.4.0 to 4.4.13 and 4.6.0 to 4.6.3.
What causes the vulnerability in CVE-2026-3201?
CVE-2026-3201 is caused by improperly controlled sequential memory allocation in the USB HID protocol dissector.
What is the impact of exploiting CVE-2026-3201?
Exploiting CVE-2026-3201 can lead to memory exhaustion, resulting in a denial of service for users of Wireshark.