Security update for wireshark
| Announcement ID: | SUSE-SU-2026:21559-1 |
|---|---|
| Release Date: | 2026-05-06T00:08:30Z |
| Rating: | important |
| References: |
|
| Cross-References: |
|
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 33 vulnerabilities can now be installed.
Description:
This update for wireshark fixes the following issues
- CVE-2026-3201: missing limit checks in USB HID protocol dissector's
parse_report_descriptorfunction can lead to memory exhaustion (bsc#1258907). - CVE-2026-3203: missing length checks in the RF4CE Profile protocol dissector can lead to illegal memory access and crash (bsc#1258909).
- CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757).
- CVE-2026-5401: AFP dissector crash (bsc#1263756).
- CVE-2026-5403: SBC audio codec crash (bsc#1263765).
- CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766).
- CVE-2026-5405: RDP dissector crash (bsc#1263767).
- CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754).
- CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753).
- CVE-2026-5408: BT-DHT dissector crash (bsc#1263752).
- CVE-2026-5409: Monero dissector crash (bsc#1263751).
- CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750).
- CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749).
- CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809).
- CVE-2026-5657: iLBC audio codec crash (bsc#1263747).
- CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746).
- CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745).
- CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744).
- CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743).
- CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742).
- CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741).
- CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739).
- CVE-2026-6529: iLBC audio codec crash (bsc#1263737).
- CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736).
- CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735).
- CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734).
- CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733).
- CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732).
- CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731).
- CVE-2026-6537: ZigBee dissector crash (bsc#1263729).
- CVE-2026-6538: BEEP dissector crash (bsc#1263728).
- CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762).
- CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726).
Changes for wireshark:
- Updated to 4.4.15
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-702=1 -
SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-702=1
Package List:
-
SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
- libwsutil16-debuginfo-4.4.15-160000.1.1
- wireshark-debuginfo-4.4.15-160000.1.1
- libwiretap15-debuginfo-4.4.15-160000.1.1
- wireshark-debugsource-4.4.15-160000.1.1
- wireshark-ui-qt-4.4.15-160000.1.1
- libwireshark18-debuginfo-4.4.15-160000.1.1
- libwsutil16-4.4.15-160000.1.1
- libwireshark18-4.4.15-160000.1.1
- wireshark-ui-qt-debuginfo-4.4.15-160000.1.1
- wireshark-devel-4.4.15-160000.1.1
- libwiretap15-4.4.15-160000.1.1
- wireshark-4.4.15-160000.1.1
-
SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
- libwsutil16-debuginfo-4.4.15-160000.1.1
- wireshark-debuginfo-4.4.15-160000.1.1
- libwiretap15-debuginfo-4.4.15-160000.1.1
- wireshark-debugsource-4.4.15-160000.1.1
- wireshark-ui-qt-4.4.15-160000.1.1
- libwireshark18-debuginfo-4.4.15-160000.1.1
- libwsutil16-4.4.15-160000.1.1
- libwireshark18-4.4.15-160000.1.1
- wireshark-ui-qt-debuginfo-4.4.15-160000.1.1
- wireshark-devel-4.4.15-160000.1.1
- libwiretap15-4.4.15-160000.1.1
- wireshark-4.4.15-160000.1.1
References:
- https://www.suse.com/security/cve/CVE-2026-3201.html
- https://www.suse.com/security/cve/CVE-2026-3203.html
- https://www.suse.com/security/cve/CVE-2026-5299.html
- https://www.suse.com/security/cve/CVE-2026-5401.html
- https://www.suse.com/security/cve/CVE-2026-5403.html
- https://www.suse.com/security/cve/CVE-2026-5404.html
- https://www.suse.com/security/cve/CVE-2026-5405.html
- https://www.suse.com/security/cve/CVE-2026-5406.html
- https://www.suse.com/security/cve/CVE-2026-5407.html
- https://www.suse.com/security/cve/CVE-2026-5408.html
- https://www.suse.com/security/cve/CVE-2026-5409.html
- https://www.suse.com/security/cve/CVE-2026-5653.html
- https://www.suse.com/security/cve/CVE-2026-5654.html
- https://www.suse.com/security/cve/CVE-2026-5656.html
- https://www.suse.com/security/cve/CVE-2026-5657.html
- https://www.suse.com/security/cve/CVE-2026-6519.html
- https://www.suse.com/security/cve/CVE-2026-6520.html
- https://www.suse.com/security/cve/CVE-2026-6521.html
- https://www.suse.com/security/cve/CVE-2026-6522.html
- https://www.suse.com/security/cve/CVE-2026-6523.html
- https://www.suse.com/security/cve/CVE-2026-6524.html
- https://www.suse.com/security/cve/CVE-2026-6527.html
- https://www.suse.com/security/cve/CVE-2026-6529.html
- https://www.suse.com/security/cve/CVE-2026-6530.html
- https://www.suse.com/security/cve/CVE-2026-6531.html
- https://www.suse.com/security/cve/CVE-2026-6532.html
- https://www.suse.com/security/cve/CVE-2026-6533.html
- https://www.suse.com/security/cve/CVE-2026-6534.html
- https://www.suse.com/security/cve/CVE-2026-6535.html
- https://www.suse.com/security/cve/CVE-2026-6537.html
- https://www.suse.com/security/cve/CVE-2026-6538.html
- https://www.suse.com/security/cve/CVE-2026-6868.html
- https://www.suse.com/security/cve/CVE-2026-6869.html
- https://bugzilla.suse.com/show_bug.cgi?id=1258907
- https://bugzilla.suse.com/show_bug.cgi?id=1258909
- https://bugzilla.suse.com/show_bug.cgi?id=1263726
- https://bugzilla.suse.com/show_bug.cgi?id=1263728
- https://bugzilla.suse.com/show_bug.cgi?id=1263729
- https://bugzilla.suse.com/show_bug.cgi?id=1263731
- https://bugzilla.suse.com/show_bug.cgi?id=1263732
- https://bugzilla.suse.com/show_bug.cgi?id=1263733
- https://bugzilla.suse.com/show_bug.cgi?id=1263734
- https://bugzilla.suse.com/show_bug.cgi?id=1263735
- https://bugzilla.suse.com/show_bug.cgi?id=1263736
- https://bugzilla.suse.com/show_bug.cgi?id=1263737
- https://bugzilla.suse.com/show_bug.cgi?id=1263739
- https://bugzilla.suse.com/show_bug.cgi?id=1263741
- https://bugzilla.suse.com/show_bug.cgi?id=1263742
- https://bugzilla.suse.com/show_bug.cgi?id=1263743
- https://bugzilla.suse.com/show_bug.cgi?id=1263744
- https://bugzilla.suse.com/show_bug.cgi?id=1263745
- https://bugzilla.suse.com/show_bug.cgi?id=1263746
- https://bugzilla.suse.com/show_bug.cgi?id=1263747
- https://bugzilla.suse.com/show_bug.cgi?id=1263749
- https://bugzilla.suse.com/show_bug.cgi?id=1263750
- https://bugzilla.suse.com/show_bug.cgi?id=1263751
- https://bugzilla.suse.com/show_bug.cgi?id=1263752
- https://bugzilla.suse.com/show_bug.cgi?id=1263753
- https://bugzilla.suse.com/show_bug.cgi?id=1263754
- https://bugzilla.suse.com/show_bug.cgi?id=1263756
- https://bugzilla.suse.com/show_bug.cgi?id=1263757
- https://bugzilla.suse.com/show_bug.cgi?id=1263762
- https://bugzilla.suse.com/show_bug.cgi?id=1263765
- https://bugzilla.suse.com/show_bug.cgi?id=1263766
- https://bugzilla.suse.com/show_bug.cgi?id=1263767
- https://bugzilla.suse.com/show_bug.cgi?id=1263809