CVE-2019-12295: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.

In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 9.0 only
  • F5 BIG-IP Access Policy Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Advanced Firewall Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Analytics: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Application Acceleration Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Application Security Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Domain Name System: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Edge Gateway: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2 (fixed in 14.1.2); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Fraud Protection Service: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2 (fixed in 14.1.2); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Global Traffic Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Link Controller: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Local Traffic Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Policy Enforcement Manager: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • F5 BIG-IP Webaccelerator: from 12.1.3.6, before 12.1.5.3 (fixed in 12.1.5.3); from 13.1.1.2, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0.3, up to and including 14.0.1; from 14.1.0, before 14.1.2.8 (fixed in 14.1.2.8); from 15.0.0, up to and including 15.0.1; version 15.1.0 only
  • Wireshark Wireshark: from 2.4.0, up to and including 2.4.14; from 2.6.0, up to and including 2.6.8; from 3.0.0, up to and including 3.0.1

Published 2019-05-23. Last modified 2026-06-17.