Wireshark disclosed CVE-2025-1492, a denial-of-service flaw that can crash the application through its Bundle Protocol and CBOR dissectors. The issue, identified through OSS-Fuzz, affects Wireshark versions 4.4.0–4.4.3 and 4.2.0–4.2.10; related fuzzing identified a stack-overflow condition while processing UDP protocol input.
An attacker could trigger the crash by injecting a malformed packet onto a monitored network or by convincing a user to open a crafted packet-capture file. Wireshark reported no known exploitation and released fixes in versions 4.4.4 and 4.2.11; organizations should upgrade affected installations or later versions.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark merged the "wscbor: Add a recursion check" remediation and closed the OSS-Fuzz issue with commit 83c73a83.
OSS-Fuzz reported CVE-2025-1492 after a minimized PCAP triggered uncontrolled recursion and a stack overflow in Wireshark's CBOR parser function wscbor_skip_next_item_internal.
Wireshark published advisory wnpa-sec-2025-01 for a crash vulnerability affecting Bundle Protocol and CBOR dissectors in versions 4.4.0–4.4.3 and 4.2.0–4.2.10. It said malformed network packets or capture files could trigger a crash, reported no known exploitation, and recommended upgrading to 4.4.4, 4.2.11, or later.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
gitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.