
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3201 is a memory exhaustion vulnerability in the USB HID protocol dissector of Wireshark that allows denial of service. It affects Wireshark versions 4.4.0 through 4.4.13 and 4.6.0 through 4.6.3. The vulnerability was disclosed on February 25, 2026, with patches released shortly after. NVD assigns a CVSS v3.1 base score of 7.5 (High), while the CNA (GitLab Inc.) scores it 4.7 (Medium) reflecting the local attack vector and required user interaction (Wireshark Advisory, Red Hat Bugzilla).
The root cause is improperly controlled sequential memory allocation (CWE-1325) and allocation of resources without limits or throttling (CWE-770) in Wireshark's USB HID protocol dissector. When parsing a specially crafted packet capture file, the dissector performs unbounded memory allocations, exhausting available system memory. Exploitation requires a user to open a malicious .pcap or packet capture file containing crafted USB HID data — no network-facing attack surface is involved. A proof-of-concept issue is tracked at the Wireshark GitLab repository (GitLab Issue, Wireshark Advisory).
Successful exploitation causes Wireshark to exhaust available memory, resulting in an application crash and denial of service. The impact is limited to availability — there is no confidentiality or integrity impact, and no code execution is possible. The scope is confined to the affected Wireshark process on the local system, with no lateral movement potential (Wireshark Advisory, Red Hat Bugzilla).
.pcap or .pcapng file containing USB HID protocol packets designed to trigger unbounded sequential memory allocations in the dissector..pcap / .pcapng files containing USB HID traffic delivered via email or file sharing platforms.wireshark, tshark) terminating abnormally with out-of-memory errors or crash dumps after opening a specific capture file./var/log/syslog, Windows Event Log) recording OOM (out-of-memory) kill events or application crash events attributed to the Wireshark process.Users should upgrade to Wireshark 4.4.14 or later (for the 4.4.x branch) or 4.6.4 or later (for the 4.6.x branch) to remediate this vulnerability. Red Hat Enterprise Linux 10 users can apply the fix via errata RHSA-2026:9666. As a workaround, restrict users from opening untrusted or unsolicited packet capture files, and educate analysts to avoid opening .pcap files from unknown sources. SUSE, Fedora, Debian, and other Linux distributions have also released updated packages (Wireshark Advisory, Red Hat Errata, Red Hat Bugzilla).
The Wireshark project announced the fix via its mailing lists and security advisory page, with the 4.6.4 and 4.4.14 releases receiving coverage from Linux-focused outlets such as Linuxiac and LinuxCompatible. SUSE, Fedora, Debian, and AlmaLinux all issued downstream security updates. Community reaction has been measured given the limited exploitability — no significant alarm was raised, and the vulnerability is generally regarded as low-risk due to the requirement for user interaction and local access (Linuxiac, Wireshark Users List).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."