wnpa-sec-2026-10 · FC-SWILS dissector crash
Summary
Name: FC-SWILS dissector crash
Docid: wnpa-sec-2026-10
Date: April 29, 2026
Affected versions: 4.6.0 to 4.6.4, 4.4.0 to 4.4.14
Fixed versions: 4.6.5, 4.4.15
References:
Wireshark issue 21070.
CVE-2026-5406.
Details
Description
The FC-SWILS dissector could crash.
Impact
Discovered by Brendan Coles. We are unaware of any exploits for this issue. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Resolution
Upgrade to Wireshark 4.6.5, 4.4.15 or later.