Wireshark disclosed CVE-2024-11595, an infinite-loop flaw in the FiveCo RAP (5CoRAP) protocol dissector. A specially malformed network packet or packet-capture file can cause Wireshark or TShark to consume excessive CPU resources while parsing traffic, creating a denial-of-service condition for analysts opening the capture or processing it automatically.
Wireshark’s ASan Menagerie fuzzing detected the hang in a crafted PCAP after TShark processes exceeded their CPU time limits. The root cause involved handling excessive items without correctly advancing the parsing offset; it was corrected through merge request !17829 and commit d8ca9fc3. The affected releases are Wireshark 4.4.0–4.4.1 and 4.2.0–4.2.8; upgrades to 4.4.2 or 4.2.9 resolve the issue. Wireshark reported no known exploitation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark merged merge request !17829 and closed issue #20176 with commit d8ca9fc3, remediating the excessive-CPU condition by advancing the 5CoRAP parsing offset correctly.
Wireshark's automated ASan Menagerie fuzzing detected a CPU-time-limit hang while TShark processed a crafted capture file on the release-4.4 branch. The issue was traced to the 5CoRAP dissector failing to advance its parsing offset correctly when handling too many items.
Wireshark published advisory wnpa-sec-2024-14 for CVE-2024-11595, an infinite-loop flaw affecting the FiveCo RAP dissector in versions 4.4.0–4.4.1 and 4.2.0–4.2.8. The issue was fixed in versions 4.4.2 and 4.2.9; Wireshark said it was found through internal testing and had no known exploitation.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.