CVE-2026-3201

Plain English Summary

AI-powered analysis for quick understanding

An attacker can cause Wireshark to crash by sending specially crafted USB HID protocol data, leading to a denial of service. This vulnerability affects specific versions of Wireshark, so users running those versions are at risk if they analyze malicious data.

Technical Description

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References