CVE-2026-6525: NULL Pointer Dereference in Wireshark
Published May 2, 2026
·Updated
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
Affected Software
2 affected components
Wireshark Wireshark>=4.6.0<=4.6.4
Wireshark Wireshark>=4.6.0<4.6.5
Remediation
Information
Upgrade to version 4.6.5 or above
Patch Available
Event History
May 2, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-6525?
CVE-2026-6525 is classified as a high-severity vulnerability due to its potential to crash Wireshark.
2
How do I fix CVE-2026-6525?
To fix CVE-2026-6525, upgrade Wireshark to version 4.6.5 or later.
3
What versions of Wireshark are affected by CVE-2026-6525?
CVE-2026-6525 affects Wireshark versions 4.6.0 to 4.6.4.
4
What type of vulnerability is CVE-2026-6525?
CVE-2026-6525 is a NULL Pointer Dereference vulnerability found in the IEEE 802.11 protocol dissector.
5
What impact does CVE-2026-6525 have on Wireshark?
CVE-2026-6525 can cause Wireshark to crash when processing certain IEEE 802.11 packet data.