Wireshark disclosed CVE-2024-11596, a denial-of-service flaw in its ECMP dissector that can crash Wireshark or the command-line tshark utility when they process malformed ECMP traffic. An attacker could trigger the condition by injecting crafted packets onto a monitored network or persuading an analyst or automated processing system to open a malicious packet-capture file; testing showed tshark terminating with a buffer-overflow detection error.
The affected releases are Wireshark 4.4.0 through 4.4.1 and 4.2.0 through 4.2.8. Wireshark corrected the string-buffer arithmetic defect in versions 4.4.2 and 4.2.9; disabling ECMP dissection also prevented the observed crash. No exploitation was known when the advisory was issued.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Wireshark merged merge requests !18074, !18075, and !18076 to resolve an ECMP dissector flaw triggered by a crafted packet capture; the GitLab issue was closed by John Thacker. The changes were titled “ECMP: Exorcise a string buffer arithmetic gremlin.”
The Wireshark ECMP dissector vulnerability was assigned CVE-2024-11596.
Wireshark published advisory wnpa-sec-2024-15 for an ECMP dissector vulnerability that can crash the application when it processes malformed network packets or packet-capture files. The advisory identified affected versions 4.4.0–4.4.1 and 4.2.0–4.2.8, stated no exploitation was known, and said the issue was fixed in versions 4.4.2 and 4.2.9.
Sake Blok referenced commits 8fd60c64 and 06e0b0bb in connection with the ECMP dissector issue.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.