CVE-2017-6014: Debian Linux

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attempts to read the same zero length packet. This will quickly exhaust all system memory.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Wireshark Wireshark: up to and including 2.2.4

Published 2017-02-17. Last modified 2026-06-17.