Release date:
2026-08-11 20:16:23 UTC
Description:
- Add wireshark-0019-epan-add-simple-recursion-checks.patch: backport the
increment/decrement_dissection_depth() API, a prerequisite for the
recursion-depth fixes below (3.4.10 has no such API)
- CVE-2023-1994: GQUIC dissector: fix a NULL pointer dereference
- CVE-2024-4853: editcap: do not memmove more than the allocated buffer holds
- CVE-2024-4855: editcap, libwiretap: do not use the array of initial decryption
secrets after it has been freed
- CVE-2026-15164: ciscodump: do not try to write more than PACKET_MAX_SIZE
- CVE-2026-15167: DBS Etherwatch reader: keep buffer slack for an extra byte
- CVE-2023-1993: LISP dissector: do not read past the LCAF payload length
- CVE-2026-6867: SMB2 dissector: put bounds on total chained compression
- CVE-2026-15172: FMP/NOTIFY dissector: stop precomputing the HandleList length
- CVE-2026-15174: catapult-dct2000 dissector: cap the E-DCH no_ddi_entries
count at MAX_EDCH_DDIS
- CVE-2026-5407: SMB2 dissector: check for offset overflow in two more places
- CVE-2026-6534: USB HID dissector: skip items with a report size of zero
- CVE-2026-6522: RPKI-RTR dissector: check for overflow in the unknown PDU
type case
- CVE-2026-5404: K12 reader: fix a possible stack overflow when writing
- CVE-2026-6529: iLBC codec plugin: report the proper decoded length in the
multiframe case
- CVE-2026-6530: DCP-ETSI dissector: reject a Reed-Solomon reassembly whose
total size is not fcount * plen
- CVE-2026-6870: GSM RP dissector: stop using a global for reassembly state
- CVE-2026-6869: WebSocket dissector: put bounds on zlib decompression
- CVE-2026-6521: OpenFlow v5 dissector: bound the OXM, action and match walks
so a crafted message cannot drive an infinite loop
- CVE-2026-6526: HTTP dissector: check the strstr() results before
dereferencing them
- CVE-2026-6532: kismet dissector: fix a heap buffer overflow
- CVE-2026-5401: AFP Spotlight dissector: add recursion checks
- CVE-2026-5406: fcswils dissector: add recursion checks
- CVE-2026-5408: BT DHT dissector: add recursion checks
- CVE-2026-6538: BEEP dissector: prevent overflow and add recursion checks
- CVE-2026-6527: asn2wrs and the generated ASN.1 dissectors: treat open types
as potentially cyclic and add recursion checks
- CVE-2026-6535: epan: fix potential overflows in zlib decompression
Updated packages:
-
wireshark-3.4.10-4.el9_2.tuxcare.els13.x86_64.rpm
sha:ec44482ea748405e3b584dd65394e252d7f91a1917ea38811424833adf0a0416
-
wireshark-cli-3.4.10-4.el9_2.tuxcare.els13.i686.rpm
sha:ebea8e8b706ca02a1af6f5fac530a0f4d7556b1ca60f36acbd01c398d34d0c4e
-
wireshark-cli-3.4.10-4.el9_2.tuxcare.els13.x86_64.rpm
sha:9971c681979271ae34800d445e40fc87b7f9e3387be9ddcd431798c5966b9820
-
wireshark-devel-3.4.10-4.el9_2.tuxcare.els13.i686.rpm
sha:1b303f177fb376b9e9fb524561cae984557c2550d1aa1bd362b6075dbab831cf
-
wireshark-devel-3.4.10-4.el9_2.tuxcare.els13.x86_64.rpm
sha:5aed048836228d1c334c36bfa7051ce53af643588cb42e3ece4a517c492dc800
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.