{"id":"openSUSE-SU-2026:20685-1","summary":"Security update for wireshark","details":"This update for wireshark fixes the following issues\n\n- CVE-2026-3201: missing limit checks in USB HID protocol dissector's `parse_report_descriptor` function can lead to\n  memory exhaustion (bsc#1258907).\n- CVE-2026-3203: missing length checks in the RF4CE Profile protocol dissector can lead to illegal memory access and\n  crash (bsc#1258909).\n- CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757).\n- CVE-2026-5401: AFP dissector crash (bsc#1263756).\n- CVE-2026-5403: SBC audio codec crash (bsc#1263765).\n- CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766).\n- CVE-2026-5405: RDP dissector crash (bsc#1263767).\n- CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754).\n- CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753).\n- CVE-2026-5408: BT-DHT dissector crash (bsc#1263752).\n- CVE-2026-5409: Monero dissector crash (bsc#1263751).\n- CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750).\n- CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749).\n- CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809).\n- CVE-2026-5657: iLBC audio codec crash (bsc#1263747).\n- CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746).\n- CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745).\n- CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744).\n- CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743).\n- CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742).\n- CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741).\n- CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739).\n- CVE-2026-6529: iLBC audio codec crash (bsc#1263737).\n- CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736).\n- CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735).\n- CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734).\n- CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733).\n- CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732).\n- CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731).\n- CVE-2026-6537: ZigBee dissector crash (bsc#1263729).\n- CVE-2026-6538: BEEP dissector crash (bsc#1263728).\n- CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762).\n- CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726).\n\nChanges for wireshark:\n\n- Updated to 4.4.15\n","modified":"2026-05-09T18:24:34.756798Z","published":"2026-05-06T00:14:18Z","related":["CVE-2026-3201","CVE-2026-3203","CVE-2026-5299","CVE-2026-5401","CVE-2026-5403","CVE-2026-5404","CVE-2026-5405","CVE-2026-5406","CVE-2026-5407","CVE-2026-5408","CVE-2026-5409","CVE-2026-5653","CVE-2026-5654","CVE-2026-5656","CVE-2026-5657","CVE-2026-6519","CVE-2026-6520","CVE-2026-6521","CVE-2026-6522","CVE-2026-6523","CVE-2026-6524","CVE-2026-6527","CVE-2026-6529","CVE-2026-6530","CVE-2026-6531","CVE-2026-6532","CVE-2026-6533","CVE-2026-6534","CVE-2026-6535","CVE-2026-6537","CVE-2026-6538","CVE-2026-6868","CVE-2026-6869"],"upstream":["CVE-2026-3201","CVE-2026-3203","CVE-2026-5299","CVE-2026-5401","CVE-2026-5403","CVE-2026-5404","CVE-2026-5405","CVE-2026-5406","CVE-2026-5407","CVE-2026-5408","CVE-2026-5409","CVE-2026-5653","CVE-2026-5654","CVE-2026-5656","CVE-2026-5657","CVE-2026-6519","CVE-2026-6520","CVE-2026-6521","CVE-2026-6522","CVE-2026-6523","CVE-2026-6524","CVE-2026-6527","CVE-2026-6529","CVE-2026-6530","CVE-2026-6531","CVE-2026-6532","CVE-2026-6533","CVE-2026-6534","CVE-2026-6535","CVE-2026-6537","CVE-2026-6538","CVE-2026-6868","CVE-2026-6869"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258907"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258909"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263726"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263728"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263729"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263731"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263732"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263733"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263734"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263735"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263736"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263737"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263739"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263741"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263742"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263743"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263744"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263745"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263746"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263750"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263753"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263754"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263756"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263757"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263762"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263765"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263766"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263767"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263809"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3203"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5653"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5654"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5656"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5657"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6520"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6522"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6531"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6532"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6534"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6535"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6537"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6538"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6869"}],"schema_version":"1.7.5"}