Wireshark Sharkd Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Wireshark sharkd utility, specifically in versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14. The issue arises from a heap-buffer-overflow in the frames method, triggered by a cached filter bitmap from previously loaded capture files. This flaw allows for a crash in the sharkd process.

Impact

Exploitation of this vulnerability leads to a crash of the sharkd utility, causing a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by loading a smaller pcap file into sharkd, applying a filter that matches some but not all frames, and then loading a second pcap file with a larger frame count that is filtered in a way to cause the out-of-bounds read, such as by matching frames that are further along in the capture.

Remediation

Users are advised to upgrade to Wireshark versions 4.6.5, 4.4.15 or later.

Added: Apr 30, 2026, 6:18 AM
Updated: Apr 30, 2026, 6:18 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
3.1
exploitability
4.6
remediation
7.7
relevance
7.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.