Wireshark disclosed CVE-2025-5601, a denial-of-service flaw in its dissection engine’s column utility handling. A remote attacker could inject a malformed packet onto a monitored network, or trick an analyst into opening a crafted capture file, to crash Wireshark or TShark. The affected releases are Wireshark 4.4.0–4.4.6 and 4.2.0–4.2.11; Wireshark reported no known exploitation and said the issue was identified through internal testing.
Fuzzing of a crafted PCAP uncovered an out-of-bounds heap write in CLNP dissection paths that invoked column-handling functions, corrupting heap metadata and causing Valgrind to abort. The remediation constrains column-fence handling during prepending so it cannot exceed the column size. Wireshark’s advisory identifies 4.2.12 and 4.4.7 as fixed releases, while the associated development issue was subsequently retargeted to 4.4.8, so organizations should deploy the latest supported Wireshark maintenance release.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark closed issue #20509 after fixes were merged, including a change preventing column fences from exceeding column size during prepending. John Thacker closed the issue with commit 53213086.
Wireshark's automated Valgrind Menagerie fuzz job found out-of-bounds heap writes while TShark processed a crafted PCAP on the release-4.4 branch. The writes originated in CLNP dissection paths invoking column utility functions and corrupted heap metadata.
Wireshark published advisory wnpa-sec-2025-02 for CVE-2025-5601, a dissection-engine crash caused by a column utility module bug affecting versions 4.4.0–4.4.6 and 4.2.0–4.2.11. Wireshark identified the issue through internal testing, stated it was unaware of exploitation, and listed versions 4.4.7 and 4.2.12 as fixes.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.