|
|
Log in / Subscribe / Register

Debian alert DLA-4479-1 (wireshark)

From:  Jochen Sprickerhof <jspricke@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4479-1] wireshark security update
Date:  Mon, 16 Feb 2026 14:51:26 +0100
Message-ID:  <aZMg3jHxfCTTNhZR@fenchel>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4479-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Jochen Sprickerhof February 16, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : wireshark Version : 3.4.16-0+deb11u2 CVE ID : CVE-2024-9781 CVE-2024-11596 CVE-2025-5601 CVE-2025-11626 CVE-2025-13499 CVE-2025-13945 CVE-2025-13946 CVE-2026-0960 Debian Bug : Multiple vulnerabilities have been fixed in the network traffic analyzer Wireshark. CVE-2024-9781 AppleTalk and RELOAD Framing dissector crash allows denial of service via packet injection or crafted capture file. CVE-2024-11596 ECMP dissector crash allows denial of service via packet injection or crafted capture file. CVE-2025-5601 Column handling crashes allows denial of service via packet injection or crafted capture file. CVE-2025-11626 MONGO dissector infinite loop allows denial of service. CVE-2025-13499 Kafka dissector crash allows denial of service. CVE-2025-13945 HTTP3 dissector crash allows denial of service. CVE-2025-13946 MEGACO dissector infinite loop in allows denial of service. CVE-2026-0960 HTTP3 protocol dissector infinite loop allows denial of service. For Debian 11 bullseye, these problems have been fixed in version 3.4.16-0+deb11u2. We recommend that you upgrade your wireshark packages. For the detailed security status of wireshark please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wireshark Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEc7KZy9TurdzAF+h6W//cwljmlDMFAmmTINoACgkQW//cwljm lDOofw/+PAcOtKWQNJLbxpAgsLReYgMOG3yrKnR8tvTGtR1i4nj5NZkmlJP8+ZxQ JdjhCkjTLStQbQ8wEroQwNQ1jAbAC7dQ9XX7ZgcohYk7ov32aJf4GBhQJlS5aqLG rBAMBIzf6SuDXVnRsYZWRIIqKsz/VThYgAh16dJW8larne2qaSSYD5fXXzQtK6iD y/UFtd1hm7bDByfmu6uTHbADW2ogrFGH46j6gXZZxbkgV2XUt/RJMAfjIAZcyXbq Qzn78w5nTPpuszWBv5TMvypWsuzLf3vHQpWlBuYaRWatRqYErVQsn7HUN5NDVJ1I QqEivBfeYUODVhbDGmmrvgj/+kQctVSJlX6w2FMWTgHEokUbsrUKJohatZIo42iT wDqLxk6XRyAstBUjNdztfD2DVskeW8RJYaZFlUFnYD5gw2wG600bgIAsQ3pMMAeL 5WaL5kkVTR6GM8vwdJlGx3N0o8M39VyGbJ+OP9c+fdpFIpxP4Nnq69YuvgKrKJi5 ta/rBXLGeoDrKW2ZbH3CjIr7YgwY4QEXRx6tO87aqlgsr0Ga6aSp/cC7P2G6vndp mmYckWWD6F1N7X8Xs5WQXk7ZgJJOUoaAdChP/MKFXt9tR59MLHwC6jMJTykgwO/N rJg10vLx5GNQLBJU04vcRGMEL0yC36V9qZxyD9EedDebKuhoGG8= =4+0f -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds