CVE-2026-6534: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wiresharkto a version that resolves this vulnerability.Fixed in 4.6.5 - Upgrade
Upgrade
wiresharkto a version that resolves this vulnerability.Fixed in 4.6.5 or above
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6534?
CVE-2026-6534 is categorized as a high-severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2026-6534?
To fix CVE-2026-6534, you should upgrade to Wireshark version 4.6.5 or later, or to version 4.4.15 or later.
What is the impact of CVE-2026-6534?
The impact of CVE-2026-6534 is an infinite loop in Wireshark's USB HID protocol dissector, which can lead to a denial of service.
Which versions of Wireshark are affected by CVE-2026-6534?
Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 are affected by CVE-2026-6534.
What components are involved in CVE-2026-6534?
CVE-2026-6534 involves the USB HID protocol dissector component of Wireshark.