CVE-2026-9759

medium
Published 2026-05-27 · Modified 2026-05-29
CVSS v3
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
5.5

Description

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

Predictions

Exploit likelihood
55%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-9759 NameCVE-2026-9759 DescriptionROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source…

CVE-2026-9759

NameCVE-2026-9759
DescriptionROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wireshark (PTS)bullseye3.4.10-0+deb11u1vulnerable
bullseye (security)3.4.16-0+deb11u2vulnerable
bookworm, bookworm (security)4.0.17-0+deb12u3vulnerable
trixie (security), trixie4.4.15-0+deb13u1vulnerable
forky, sid4.6.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wiresharksource(unstable)4.6.6-1

Notes

[trixie] - wireshark <postponed> (Minor issue, fix along with future update)
[bookworm] - wireshark <no-dsa> (Minor issue)
https://www.wireshark.org/security/wnpa-sec-2026-51.html
https://gitlab.com/wireshark/wireshark/-/work_items/21243

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - wireshark <postponed> (Minor issue, fix along with future update)[bookworm] - wireshark <no-dsa> (Minor issue)https://www.wireshark.org/security/wnpa-sec-2026-51.htmlhttps://gitlab.com/wireshark/wireshark/-/work_items/21243

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed4.6.6-1
debian debiansidfixed4.6.6-1
debian debiantrixieaffected
suse slesaffected

References

CWEs

CWE-476

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.