CVE-2026-15165: Heap-based Buffer Overflow in Wireshark
Published Jul 8, 2026
·Updated
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Affected Software
2 affected components
Wireshark Wireshark>=4.6.0<=4.6.6
Wireshark Wireshark>=4.6.0<4.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.7
Event History
Jul 8, 2026
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15165?
The severity of CVE-2026-15165 is rated as medium, with a score of 5.5.
2
What type of vulnerability is CVE-2026-15165?
CVE-2026-15165 is a heap-based buffer overflow vulnerability.
3
How can I fix CVE-2026-15165?
To fix CVE-2026-15165, update Wireshark to version 4.6.7 or later.
4
What impact does CVE-2026-15165 have on Wireshark?
CVE-2026-15165 can cause a denial of service by crashing the TLS ECH decryptor in affected versions of Wireshark.
5
In which versions of Wireshark does CVE-2026-15165 exist?
CVE-2026-15165 affects Wireshark versions 4.6.0 to 4.6.6.