{"id":"SUSE-SU-2026:1169-1","summary":"Security update for wireshark","details":"This update for wireshark fixes the following issues:\n\nUpdate Wireshark to version 4.6.4 (jsc#PED-15400).\n\n- CVE-2024-9780: ITS dissector crash (bsc#1231475).\n- CVE-2024-9781: AppleTalk and RELOAD Framing dissector crash (bsc#1231476).\n- CVE-2024-11595: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark (bsc#1233594).\n- CVE-2024-11596: Buffer Over-read in Wireshark (bsc#1233593).\n- CVE-2025-1492: Uncontrolled Recursion in Wireshark (bsc#1237414).\n- CVE-2025-5601: Column handling crashes in Wireshark allows denial of service (bsc#1244081).\n- CVE-2025-9817: NULL Pointer Dereference in ssh dissector (bsc#1249090).\n- CVE-2025-13499: a malformed packet can lead to a Kafka dissector crash (bsc#1254108).\n- CVE-2025-13674: injecting a malformed packet can cause a crash (bsc#1254262).\n- CVE-2025-13945: HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service (bsc#1254471).\n- CVE-2025-13946: MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of\n  service (bsc#1254472).\n- CVE-2026-0959: denial of service via IEEE 802.11 protocol dissector crash (bsc#1256734).\n- CVE-2026-0960: denial of Service via HTTP3 protocol dissector infinite loop (bsc#1256736).\n- CVE-2026-0961: denial of Service vulnerability in BLF file parser (bsc#1256738).\n- CVE-2026-0962: denial of Service via SOME/IP-SD protocol dissector crash (bsc#1256739).\n- CVE-2026-3201: missing limit checks in USB HID protocol dissector's `parse_report_descriptor` function can lead to\n  memory exhaustion (bsc#1258907).\n- CVE-2026-3202: missing checks in NTS-KE protocol dissector can lead to crash (bsc#1258908).\n- CVE-2026-3203: missing length checks in the RF4CE Profile protocol dissector can lead to illegal memory access and\n  crash (bsc#1258909).\n\nAlso libvirt was rebuilt against wireshark for the libvirt plugin.\n","modified":"2026-04-03T07:45:38.640463Z","published":"2026-04-02T08:29:30Z","related":["CVE-2024-11595","CVE-2024-11596","CVE-2024-9780","CVE-2024-9781","CVE-2025-13499","CVE-2025-13674","CVE-2025-13945","CVE-2025-13946","CVE-2025-1492","CVE-2025-5601","CVE-2025-9817","CVE-2026-0959","CVE-2026-0960","CVE-2026-0961","CVE-2026-0962","CVE-2026-3201","CVE-2026-3202","CVE-2026-3203"],"upstream":["CVE-2024-11595","CVE-2024-11596","CVE-2024-9780","CVE-2024-9781","CVE-2025-13499","CVE-2025-13674","CVE-2025-13945","CVE-2025-13946","CVE-2025-1492","CVE-2025-5601","CVE-2025-9817","CVE-2026-0959","CVE-2026-0960","CVE-2026-0961","CVE-2026-0962","CVE-2026-3201","CVE-2026-3202","CVE-2026-3203"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261169-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231475"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231476"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233594"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237414"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249090"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254108"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254262"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254471"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254472"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256734"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256736"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256738"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256739"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258907"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258908"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258909"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-11595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-11596"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-9780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-9781"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13674"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-1492"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-5601"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-9817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3202"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3203"}],"affected":[{"package":{"name":"libvirt","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.0-150700.4.19.1"}]}],"ecosystem_specific":{"binaries":[{"libvirt-libs":"11.0.0-150700.4.19.1","libwireshark19":"4.6.4-150700.21.8.1","libwiretap16":"4.6.4-150700.21.8.1","libwsutil17":"4.6.4-150700.21.8.1","wireshark":"4.6.4-150700.21.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1169-1.json"}},{"package":{"name":"wireshark","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.4-150700.21.8.1"}]}],"ecosystem_specific":{"binaries":[{"libwireshark19":"4.6.4-150700.21.8.1","libwiretap16":"4.6.4-150700.21.8.1","libwsutil17":"4.6.4-150700.21.8.1","wireshark":"4.6.4-150700.21.8.1","libvirt-libs":"11.0.0-150700.4.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1169-1.json"}},{"package":{"name":"wireshark","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.4-150700.21.8.1"}]}],"ecosystem_specific":{"binaries":[{"wireshark-devel":"4.6.4-150700.21.8.1","wireshark-ui-qt":"4.6.4-150700.21.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1169-1.json"}},{"package":{"name":"libvirt","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.0-150700.4.19.1"}]}],"ecosystem_specific":{"binaries":[{"libvirt-daemon-driver-nwfilter":"11.0.0-150700.4.19.1","libvirt-daemon-hooks":"11.0.0-150700.4.19.1","libvirt-daemon-qemu":"11.0.0-150700.4.19.1","libvirt-daemon-xen":"11.0.0-150700.4.19.1","libvirt-doc":"11.0.0-150700.4.19.1","libvirt-client":"11.0.0-150700.4.19.1","libvirt-daemon-config-nwfilter":"11.0.0-150700.4.19.1","libvirt-daemon-driver-libxl":"11.0.0-150700.4.19.1","libvirt-daemon-driver-secret":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-scsi":"11.0.0-150700.4.19.1","libvirt-daemon-driver-qemu":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-rbd":"11.0.0-150700.4.19.1","libvirt-daemon-plugin-sanlock":"11.0.0-150700.4.19.1","libvirt-daemon":"11.0.0-150700.4.19.1","libvirt-nss":"11.0.0-150700.4.19.1","libvirt-daemon-driver-network":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-disk":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-iscsi-direct":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-mpath":"11.0.0-150700.4.19.1","libvirt-daemon-proxy":"11.0.0-150700.4.19.1","libvirt-devel":"11.0.0-150700.4.19.1","libvirt":"11.0.0-150700.4.19.1","libvirt-client-qemu":"11.0.0-150700.4.19.1","libvirt-daemon-common":"11.0.0-150700.4.19.1","libvirt-daemon-config-network":"11.0.0-150700.4.19.1","libvirt-daemon-driver-interface":"11.0.0-150700.4.19.1","libvirt-daemon-lock":"11.0.0-150700.4.19.1","libvirt-daemon-plugin-lockd":"11.0.0-150700.4.19.1","libvirt-daemon-driver-nodedev":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-core":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-iscsi":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage-logical":"11.0.0-150700.4.19.1","libvirt-daemon-driver-storage":"11.0.0-150700.4.19.1","libvirt-daemon-log":"11.0.0-150700.4.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1169-1.json"}}],"schema_version":"1.7.5"}