CVE-2026-6520: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wireshark (OpenFlow v6 protocol dissector)to a version that resolves this vulnerability.Fixed in 4.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6520?
The severity of CVE-2026-6520 is classified as a denial of service vulnerability that can cause an infinite loop.
How do I fix CVE-2026-6520?
To fix CVE-2026-6520, upgrade Wireshark to version 4.6.5 or later, or to version 4.4.15 or later.
Which versions of Wireshark are affected by CVE-2026-6520?
CVE-2026-6520 affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14.
What impact does CVE-2026-6520 have on systems running affected versions?
CVE-2026-6520 can cause denial of service, making the application unresponsive due to an infinite loop.
Is there a workaround for CVE-2026-6520 if I cannot upgrade Wireshark?
Currently, there is no known workaround for CVE-2026-6520; upgrading to a fixed version is recommended.