The Wireshark Foundation has announced the release of version 4.4.4 of its popular network protocol analyzer, resolving a high-severity vulnerability that could allow attackers to cause a denial of service (DoS) condition by injecting malicious packets.
See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks

The update fixes CVE-2025-1492 , a serious issue in the Bundle Protocol and CBOR parsers . This flaw could lead to errors, infinite loops, and memory leaks when processing specially crafted network traffic.
Wireshark 4.4.4 is the fourth consecutive security patch in the 4.4.x series, highlighting the ongoing risks associated with tools and their importance to network security.
CVE-2025-1492 was rated 7.8 (High) on the CVSS v3.1 scale, affecting Wireshark versions 4.4.0 to 4.4.3, as well as 4.2.0 to 4.2.10.
Attackers who exploit this vulnerability could cause severe disruption to network troubleshooting, analysis, and monitoring processes by overloading systems with malformed packets.
See also: Vulnerability in Facebook Messenger for iOS allows DoS attack via emoji
The problem lies in the way Wireshark analyzers process the data structures of the Bundle Protocol, which is used in delay-tolerant networking, as well as CBOR (Compressed Binary Object Representation).

Successful exploitation could cause crash , affecting critical network diagnostics and potentially leading to extensive service outages.
According to the Wireshark security advisory (wnpa-sec-2025-01), the vulnerability affecting Wireshark 4.4.4 was discovered through automated fuzzing testing. This method injects invalid or random data into the software, with the aim of revealing any weaknesses or instability in the system.
This is consistent with historical patterns where protocol decompilers that decode network traffic were prime targets for DoS attacks. For example, previous vulnerabilities in Bluetooth, Radiotap, and AVDTP analyzers (CVE-2018-16056, CVE-2018-16057, CVE-2018-16058) allowed for errors to be caused via malformed packets or malicious files.
See also: Vulnerability in Apache Tomcat allows Dos attacks
A DoS (Denial of Service) attack is a type of cyberattack that aims to disrupt the normal operation of a network, service, or system. It is usually achieved by overloading the target's resources with excessive data traffic or requests, rendering it unable to respond to legitimate users. DoS attacks can cause significant problems, such as data loss, reduced productivity, and financial losses to businesses.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
