CVE-2026-6523: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6523?
CVE-2026-6523 is rated as a high severity denial of service vulnerability that results from an infinite loop in the Wireshark GNW protocol dissector.
How do I fix CVE-2026-6523?
To fix CVE-2026-6523, upgrade Wireshark to version 4.6.5 or later, or 4.4.15 or later.
Which versions of Wireshark are affected by CVE-2026-6523?
CVE-2026-6523 affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14.
What is the impact of exploiting CVE-2026-6523?
Exploitation of CVE-2026-6523 may result in denial of service, causing the application to become unresponsive.
Is there a workaround for CVE-2026-6523?
There is no official workaround for CVE-2026-6523; upgrading to a patched version is recommended.