Wireshark disclosed CVE-2026-6531, an uncontrolled resource consumption flaw in the SANE protocol dissector that can cause Wireshark or tshark to hang indefinitely at 100% CPU while parsing a crafted packet. The bug is in dissect_control_option_value() in packet-sane.c, where an attacker-controlled array_length can drive an effectively empty loop for up to roughly 2^31 iterations when an invalid or unrecognized value_type is processed. The issue is reachable through SANE SANE_NET_CONTROL_OPTION request and response parsing on TCP port 6566, and a single crafted 119-byte Ethernet frame was reported as sufficient to trigger the condition.
Wireshark said the vulnerability affects versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and that fixes were released in 4.6.5 and 4.4.15. Upstream issue tracking also noted the flaw in the 4.7.0 development line before the report was closed and linked to merged fixes. The vendor classified the bug as a denial-of-service condition caused by an infinite loop in SANE packet dissection and tied its advisory to public bug report #21139.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A CVE record for CVE-2026-6531 was published by MITRE. The provided reference does not include vulnerability details beyond the existence of the CVE entry.
On April 29, 2026, Wireshark published security advisory wnpa-sec-2026-30 describing an infinite loop vulnerability in the SANE protocol dissector, tracked as CVE-2026-6531. The advisory said versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14 were affected, and that fixes were available in 4.6.5 and 4.4.15.
A GitLab issue was created reporting an uncontrolled resource consumption vulnerability in Wireshark's SANE dissector that can cause Wireshark or tshark to hang at 100% CPU when parsing a crafted packet. The report identified the bug in `dissect_control_option_value()` and noted it affected Wireshark 4.7.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcegitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.