High severity7.8NVD Advisory· Published May 1, 2026· Updated Jul 15, 2026
CVE-2026-5405
CVE-2026-5405
Description
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords6 versionspkg:rpm/almalinux/wiresharkpkg:rpm/almalinux/wireshark-clipkg:rpm/almalinux/wireshark-develpkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweedpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6
< 1:4.4.2-10.el10_2+ 5 more
- (no CPE)range: < 1:4.4.2-10.el10_2
- (no CPE)range: < 1:4.4.2-10.el10_2
- (no CPE)range: < 1:4.4.2-10.el10_2
- (no CPE)range: < 4.6.5-1.1
- (no CPE)range: < 4.2.14-150600.18.41.1
- (no CPE)range: < 4.2.14-150600.18.41.1
Patches
Vulnerability mechanics
References
7- gitlab.com/wireshark/wireshark/-/issues/21105nvdExploitIssue TrackingThird Party Advisory
- www.wireshark.org/security/wnpa-sec-2026-17.htmlnvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:20600nvd
- access.redhat.com/errata/RHSA-2026:26182nvd
- access.redhat.com/security/cve/CVE-2026-5405nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5405.jsonnvd
News mentions
1- ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News · May 4, 2026