CVE-2023-2952: Debian Linux
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
XRA dissector infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
Affected products
- Debian Debian Linux: version 10.0 only; version 12.0 only
- Wireshark Wireshark: from 3.6.0, before 3.6.14 (fixed in 3.6.14); from 4.0.0, before 4.0.6 (fixed in 4.0.6)
Published 2023-05-30. Last modified 2026-06-17.