Wireshark iLBC Audio Codec Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The issue arises from the iLBC audio codec, which can crash the application by causing a heap buffer overflow. This vulnerability is triggered when the decoder processes multiple frames of iLBC audio, writing more data into a buffer than it can safely hold.

Impact

Exploitation of this vulnerability leads to a heap buffer overflow, causing a crash in the application. However, such heap overflows can often be exploited to execute arbitrary code under certain conditions.

Reproduction

The vulnerability can be reproduced by loading a specially crafted pcap file containing multi-frame iLBC RTP packets into Wireshark. This should be done using a version of Wireshark compiled with AddressSanitizer, which will detect the heap buffer overflow. The iLBC codec should be selected in the RTP player, as the vulnerability relies on the codec being processed.

Remediation

Users can upgrade to Wireshark versions 4.6.5 or 4.4.15, where this vulnerability has been fixed.

Added: Apr 30, 2026, 7:39 AM
Updated: Apr 30, 2026, 7:39 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.3
exploitability
5.6
remediation
7.7
relevance
7.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.