<Vulnerability name="CVE-2026-15167">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-08T20:51:00</PublicDate>
    <Bugzilla id="2498277" url="https://bugzilla.redhat.com/show_bug.cgi?id=2498277" xml:lang="en:us">
wireshark: Wireshark: Denial of Service via DBS Etherwatch file parser crash
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1286</CWE>
    <Details xml:lang="en:us" source="Mitre">
DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the DBS Etherwatch file parser, leading to a crash of the application. This could result in a denial of service, making the Wireshark application unavailable to users.
    </Details>
    <Statement xml:lang="en:us">
Moderate: A denial of service vulnerability exists in Wireshark's DBS Etherwatch file parser. This flaw allows a remote attacker to trigger an application crash by processing a specially crafted file, impacting the availability of the network analysis tool. The vulnerability requires user interaction to open a malicious file or process untrusted network captures.
    </Statement>
    <Mitigation xml:lang="en:us">
Users should avoid opening or processing untrusted DBS Etherwatch files with Wireshark. Exercise caution when handling network capture files from unknown or suspicious sources. This operational control helps prevent the application from crashing due to malicious input.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-15167
https://nvd.nist.gov/vuln/detail/CVE-2026-15167
https://gitlab.com/wireshark/wireshark/-/work_items/21352
https://www.wireshark.org/security/wnpa-sec-2026-62.html
    </References>
</Vulnerability>