CVE-2019-16319: Debian Linux
High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.
In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
Affected products
- Debian Debian Linux: version 9.0 only
- Opensuse Leap: version 15.1 only
- Wireshark Wireshark: from 2.6.0, up to and including 2.6.10; from 3.0.0, up to and including 3.0.3
Published 2019-09-15. Last modified 2026-06-17.