VulnerabilityModified
CVE-2020-26418
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
MEDIUM 5.3EPSS 3.00%
Does this matter?
Lower severity and a low EPSS score (3.00%). Track it; it rarely justifies an emergency change on its own.
Description
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 3.00% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401
- Affected
- wireshark/wireshark · fedoraproject/fedora · debian/debian linux · oracle/zfs storage appliance kit
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26418.jsonThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/16739Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00008.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/
- https://security.gentoo.org/glsa/202101-12Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2020-16.htmlVendor Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26418.jsonThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/16739Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00008.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/
- https://security.gentoo.org/glsa/202101-12Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2020-16.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.