<Vulnerability name="CVE-2026-15172">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-08T20:51:20</PublicDate>
    <Bugzilla id="2498306" url="https://bugzilla.redhat.com/show_bug.cgi?id=2498306" xml:lang="en:us">
wireshark: Wireshark: Denial of service via FMP/NOTIFY protocol dissector crash
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1286</CWE>
    <Details xml:lang="en:us" source="Mitre">
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Wireshark. A local user could exploit this vulnerability by processing a specially crafted FMP/NOTIFY protocol packet. This could lead to a denial of service (DoS) due to a crash in the protocol dissector, making the application unavailable.
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact flaw in Wireshark allows a local attacker to cause a denial of service by processing a specially crafted FMP/NOTIFY protocol packet. The vulnerability requires user interaction, as an attacker must trick a local user into opening a malicious packet capture file, limiting the attack surface.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this issue, users should avoid opening untrusted or suspicious packet capture files with Wireshark. Restricting access to systems running Wireshark and ensuring that only trusted network captures are analyzed can further reduce the risk of exploitation.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-15172
https://nvd.nist.gov/vuln/detail/CVE-2026-15172
https://gitlab.com/wireshark/wireshark/-/work_items/21347
https://www.wireshark.org/security/wnpa-sec-2026-54.html
    </References>
</Vulnerability>