CVE-2024-4854: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
Affected products
- Fedoraproject Fedora: version 39 only; version 40 only
- Wireshark Wireshark: from 3.6.0, up to and including 3.6.22; from 4.0.0, up to and including 4.0.14; from 4.2.0, up to and including 4.2.4
Published 2024-05-14. Last modified 2026-06-17.