CVE-2020-26422: Oracle ZFS Storage Appliance Kit

Medium severity, CVSS 5.3. EPSS: 4.7% chance of exploitation in the next 30 days.

Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file

Affected products

  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Wireshark Wireshark: version 3.4.0 only; version 3.4.1 only

Published 2020-12-21. Last modified 2026-06-17.