CVE-2026-6522: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6522?
CVE-2026-6522 has a severity rating that indicates it can lead to a denial of service due to an infinite loop in the Wireshark RPKI-Router protocol dissector.
What versions of Wireshark are affected by CVE-2026-6522?
CVE-2026-6522 affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14.
How do I fix CVE-2026-6522?
To fix CVE-2026-6522, upgrade to a patched version of Wireshark that is beyond the affected versions.
What type of attack does CVE-2026-6522 enable?
CVE-2026-6522 enables a denial of service attack by causing an infinite loop during protocol dissection.
Is there a workaround for CVE-2026-6522?
There is no official workaround for CVE-2026-6522; upgrading to a secure version is the recommended solution.