CVE-2026-3201Patch(wireshark / wireshark)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wireshark wireshark systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1325CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wireshark

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-26); latest day: 3
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
wireshark

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-02-25: 1Mentions · 2026-02-26: 3Mentions · 2026-03-05: 3Patch / Workaround · 2026-02-26: 3Patch / Workaround · 2026-03-05: 3Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 3Technical Details · 2026-03-05: 202-2502-2603-05
Signal classification2 categories
Patch
685.7%
Disclosure
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-263
Patch3
2026-03-053
Patch3
Full discourse7 posts
  • インフォセキュアソリューションズ株式会社@InSecSol0417
    Patch

    🦈【Wireshark 4.6.4公開】 ネットワーク解析ツール「Wireshark」でUSB HID/NTS-KE/RF4CE解析時のクラッシュやメモリ枯渇を招く3件の脆弱性(CVE-2026-3201〜3203)が修正されました。 4.6系は4.6.4、4.4系は4.4.14へ更新し、常用端末のバージョンをチェックしましょう。 #企業公式相互フォロー

    Post summary

    Wireshark 4.6.4 release fixes CVE-2026-3201 to CVE-2026-3203, which caused crashes and memory exhaustion during USB HID/NTS-KE/RF4CE parsing; users should update to the latest version.

    0007079
    446 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Wireshark 4.6.4 ships security fixes for multiple dissector CVEs and restores plugin compatibility Wireshark 4.6.4 fixes three security issues (USB HID memory exhaustion CVE-2026-3201, NTS-KE crash CVE-2026-3202, RF4CE Profile crash CVE-2026-3203) and includes additional stability bug fixes, while also restoring compatibility for plugins impacted by the 4.6.1 API/ABI change. 🎯 Target: Global/Blue Team & DFIR #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.helpnetsecurity.com/2026/02/26/wireshark-4-6-4-released/

    Post summary

    Wireshark 4.6.4 releases a patch that fixes three CVEs—CVE-2026-3201, CVE-2026-3202, and CVE-2026-3203—while restoring plugin compatibility and adding stability fixes.

    0101087
    221 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Wireshark 4.6.4 がリリース:脆弱性 CVE-2026-3201/3202/3203 が FIX:DoS 攻撃やクラッシュに対応 https://iototsecnews.jp/2026/02/26/wireshark-4-6-4-released-to-patch-multiple-security-vulnerabilities/ ネットワーク解析のデファクト・スタンダード Wireshark において、特定のパケット解析中にプログラムが強制終了したり、メモリを過度に消費させたりする、深刻な脆弱性が発見され、その修正版としてバージョン 4.6.4 が公開されました。今回のアップデートは、単なる機能追加ではなく、悪意を持って細工されたキャプチャ・ファイルやライブ・トラフィックを読み込んだ際に、Wireshark 自体を攻撃対象とする解析者への攻撃を防ぐための重要なセキュリティ更新です。ご利用のチームは、ご注意ください。 #CVE20263201 #CVE20263202 #CVE20263203 #Vulnerability #Wireshark

    Post summary

    The article announces the release of Wireshark 4.6.4, which patches CVE‑2026‑3201, CVE‑2026‑3202, and CVE‑2026‑3203, addressing DoS and crash vulnerabilities, and recommends users update accordingly.

    01000143
    483 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Wireshark 4.6.4 Patches 3 CVEs Causing Dissector DoS/Crashes (USB HID, NTS-KE, RF4CE) Wireshark 4.6.4 fixes three vulnerabilities—CVE-2026-3201 (USB HID memory exhaustion), CVE-2026-3202 (NTS-KE NULL deref crash), and CVE-2026-3203 (RF4CE dissector crash)—that can be triggered by malformed traffic/pcaps to disrupt analysis workflows. 🎯 Target: Global/Network & Security Teams #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/wireshark-4-6-4-released-with-patches-for-multiple-security-vulnerabilities/

    Post summary

    Wireshark 4.6.4 addresses three CVEs (CVE-2026-3201, CVE-2026-3202, CVE-2026-3203) that cause memory exhaustion or crashes via malformed traffic, with patches now available.

    0001041
    220 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    New #USE patch advisory (SUSE-2026-0810-1) for Wireshark on #openSUSE Leap 15.6 addresses CVE-2026-3201. Read more: 👉 https://tinyurl.com/2u8upss3 #Security https://t.co/zUGu9jAaKY

    Post summary

    The advisory announces a new patch for Wireshark on openSUSE Leap 15.6 that addresses CVE-2026-3201, directing readers to a URL for more information.

    0000064
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical patch for #openSUSE Leap 15.6: Wireshark update (SUSE-SU-2026:0810-1) addresses CVE-2026-3201. This fixes a memory exhaustion vulnerability in the USB HID dissector. Read more: 👉 https://tinyurl.com/4dndufnv #Security https://t.co/LU1UOWcb6J

    Post summary

    A critical patch for openSUSE Leap 15.6 addresses CVE-2026-3201, a memory exhaustion issue in Wireshark's USB HID dissector, with a link to the SUSE advisory.

    0000066
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3201 USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service https://www.cve.org/CVERecord?id=CVE-2026-3201

    Post summary

    The CVE-2026-3201 identifies a memory exhaustion vulnerability in Wireshark’s USB HID protocol dissector that can lead to denial of service in versions 4.6.0‑4.6.3 and 4.4.0‑4.4.13.

    0000093
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwiresharkwireshark---

Explore more