{"cves":[{"id":"CVE-2026-6527","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:06:09.752889+00:00","description":"\nASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to\n4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6527","https://www.wireshark.org/security/wnpa-sec-2026-34.html","https://gitlab.com/wireshark/wireshark/-/work_items/21149"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6526","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:06:09.752889+00:00","description":"\nRTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6526","https://www.wireshark.org/security/wnpa-sec-2026-35.html","https://gitlab.com/wireshark/wireshark/-/work_items/21173"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6524","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:14:36.833218+00:00","description":"\nMySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to\n4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6524","https://www.wireshark.org/security/wnpa-sec-2026-37.html","https://gitlab.com/wireshark/wireshark/-/work_items/21172"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6523","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:22:57.412465+00:00","description":"\nGNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0\nto 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6523","https://www.wireshark.org/security/wnpa-sec-2026-38.html","https://gitlab.com/wireshark/wireshark/-/work_items/21177"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6522","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:13:39.642945+00:00","description":"\nRPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4\nand 4.4.0 to 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6522"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6521","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:59:35.652827+00:00","description":"\nOpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4\nand 4.4.0 to 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6521"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6520","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:16:26.060306+00:00","description":"\nOpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4\nand 4.4.0 to 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6520"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6519","published":"2026-04-30T00:00:00","updated_at":"2026-05-14T07:35:22.420652+00:00","description":"\nMBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0\nto 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6519"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5657","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:35:25.726686+00:00","description":"\niLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows\ndenial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5657"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5655","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T15:51:17.530053+00:00","description":"\nSDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of\nservice","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5655"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5654","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:35:54.863394+00:00","description":"\nAMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows\ndenial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5654"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5653","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T15:48:29.591226+00:00","description":"\nDCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to\n4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5653"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5419","published":"2026-04-30T00:00:00","updated_at":"2026-06-06T09:32:26.876938+00:00","description":"\nA flaw was found in gnutls. The PKCS#7 padding check, performed during\ndecryption, was not constant-time. This timing side-channel could allow a\nremote attacker to potentially leak sensitive information about the padding\nbytes through observable timing differences. This vulnerability is a form\nof information disclosure.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5419","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13","https://ubuntu.com/security/notices/USN-8284-1"],"bugs":["https://gitlab.com/gnutls/gnutls/-/issues/1815"],"patches":{"gnutls28":["upstream: https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab"]},"tags":{},"packages":[{"name":"gnutls28","source":"https://ubuntu.com/security/cve?package=gnutls28","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnutls28","debian":"https://tracker.debian.org/pkg/gnutls28","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8.13","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.8.3-1.1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.8.9-3ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.8.12-2ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8284-1"],"notices":[{"id":"USN-8284-1","title":"GnuTLS vulnerabilities","summary":"Several security issues were fixed in GnuTLS.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-20T12:57:03.881954","description":"Joshua Rogers discovered that GnuTLS did not properly handle malformed\nDTLS handshake fragments in certain cases. A remote attacker could\npossibly use this issue to obtain sensitive information, or cause a\ndenial of service. (CVE-2026-33845)\n\nHaruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did\nnot properly validate DTLS handshake fragment lengths in certain cases. A\nremote attacker could possibly use this issue to cause GnuTLS to crash,\nresulting in a denial of service, or execute arbitrary code.\n(CVE-2026-33846)\n\nOleh Konko and Joshua Rogers discovered that GnuTLS did not properly\nvalidate OCSP responses in certain cases. A remote attacker could\npossibly use this issue to bypass certificate revocation checks, leading\nto a machine-in-the-middle attack. (CVE-2026-3832)\n\nOleh Konko and Joshua Rogers discovered that GnuTLS did not properly\nhandle case-insensitive name constraints in certain cases. A remote\nattacker could possibly use this issue to bypass certificate validation,\nleading to a machine-in-the-middle attack. (CVE-2026-3833)\n\nJoshua Rogers discovered that GnuTLS did not properly order DTLS packets\nwith duplicate sequence numbers in certain cases. A remote attacker could\npossibly use this issue to cause GnuTLS to crash, resulting in a denial\nof service. (CVE-2026-42009)\n\nJoshua Rogers discovered that GnuTLS did not properly handle usernames\ncontaining NUL characters in certain RSA-PSK configurations. A remote\nattacker could possibly use this issue to bypass authentication and gain\nunintended access to services. (CVE-2026-42010)\n\nHaruto Kimura discovered that GnuTLS did not properly apply permitted\nname constraints in certain certificate validation paths. A remote\nattacker could possibly use this issue to bypass certificate validation,\nleading to a machine-in-the-middle attack. (CVE-2026-42011)\n\nOleh Konko discovered that GnuTLS incorrectly fell back to Common Name\nchecks for certain URI and SRV subject alternative names. A remote\nattacker could possibly use this issue to bypass certificate validation,\nleading to a machine-in-the-middle attack. (CVE-2026-42012)\n\nHaruto Kimura and Joshua Rogers discovered that GnuTLS incorrectly fell\nback to Common Name checks when subject alternative names were oversized.\nA remote attacker could possibly use this issue to bypass certificate\nvalidation, leading to a machine-in-the-middle attack. (CVE-2026-42013)\n\nLuigino Camastra and Joshua Rogers discovered that GnuTLS had a\nuse-after-free issue when changing PKCS#11 token security officer PINs in\ncertain cases. An attacker could possibly use this issue to cause GnuTLS\nto crash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-42014)\n\nZou Dikai discovered that GnuTLS did not properly validate PKCS#12 bag\nsizes in certain cases. An attacker could possibly use this issue to\ncause GnuTLS to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-42015)\n\nJoshua Rogers discovered that GnuTLS did not properly handle very short\npremaster secrets in certain RSA key exchange cases with PKCS#11-backed\nserver keys. A remote attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-5260)\n\nDoria Tang discovered that GnuTLS did not perform PKCS#7 padding checks\nin constant time in certain cases. A remote attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected\nUbuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-5419)","is_hidden":false,"release_packages":{"jammy":[{"name":"gnutls28","version":"3.7.3-4ubuntu1.9","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"gnutls-doc","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"guile-gnutls","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"libgnutls-dane0","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"libgnutls-openssl27","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"libgnutls28-dev","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"libgnutls30","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"},{"name":"libgnutlsxx28","version":"3.7.3-4ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.9","pocket":"security"}],"noble":[{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.6","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.8.3-1.1ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.6","pocket":"security"},{"name":"gnutls-doc","version":"3.8.3-1.1ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.6","pocket":"security"},{"name":"libgnutls-dane0t64","version":"3.8.3-1.1ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.6","pocket":"security"},{"name":"libgnutls-openssl27t64","version":"3.8.3-1.1ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.6","pocket":"security"},{"name":"libgnutls28-dev","version":"3.8.3-1.1ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.6","pocket":"security"},{"name":"libgnutls30t64","version":"3.8.3-1.1ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.6","pocket":"security"}],"questing":[{"name":"gnutls28","version":"3.8.9-3ubuntu2.2","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.8.9-3ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.2","pocket":"security"},{"name":"gnutls-doc","version":"3.8.9-3ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.2","pocket":"security"},{"name":"libgnutls-dane0t64","version":"3.8.9-3ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.2","pocket":"security"},{"name":"libgnutls-openssl27t64","version":"3.8.9-3ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.2","pocket":"security"},{"name":"libgnutls28-dev","version":"3.8.9-3ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.2","pocket":"security"},{"name":"libgnutls30t64","version":"3.8.9-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.2","pocket":"security"}],"resolute":[{"name":"gnutls28","version":"3.8.12-2ubuntu1.1","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.8.12-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.12-2ubuntu1.1","pocket":"security"},{"name":"gnutls-doc","version":"3.8.12-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.12-2ubuntu1.1","pocket":"security"},{"name":"libgnutls-dane0t64","version":"3.8.12-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.12-2ubuntu1.1","pocket":"security"},{"name":"libgnutls-openssl27t64","version":"3.8.12-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.12-2ubuntu1.1","pocket":"security"},{"name":"libgnutls28-dev","version":"3.8.12-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.12-2ubuntu1.1","pocket":"security"},{"name":"libgnutls30t64","version":"3.8.12-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.12-2ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42015","CVE-2026-42011","CVE-2026-5260","CVE-2026-42010","CVE-2026-3833","CVE-2026-42013","CVE-2026-33846","CVE-2026-42014","CVE-2026-5419","CVE-2026-42009","CVE-2026-42012","CVE-2026-3832","CVE-2026-33845"]}]},{"id":"CVE-2026-5409","published":"2026-04-30T00:00:00","updated_at":"2026-05-14T11:25:46.925180+00:00","description":"\nMonero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to\n4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5409"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5408","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:48:20.356935+00:00","description":"\nBT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to\n4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5408"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5407","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:54:54.604340+00:00","description":"\nSMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0\nto 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5407"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5406","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:09:06.527435+00:00","description":"\nFC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to\n4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5406"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5402","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T17:10:32.672527+00:00","description":"\nTLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows\ndenial of service and possible code execution","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5402"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5401","published":"2026-04-30T00:00:00","updated_at":"2026-05-14T11:52:41.297478+00:00","description":"\nAFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and\n4.4.0 to 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5401"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-5299","published":"2026-04-30T00:00:00","updated_at":"2026-05-13T16:24:00.218711+00:00","description":"\nICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0\nto 4.4.14 allows denial of service","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-5299"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":12800,"limit":20,"total_results":79316}