Red Hat Product Errata RHSA-2026:20600 - Security Advisory Issued: 2026-05-26 Updated: 2026-05-26 RHSA-2026:20600 - Security Advisory Overview Updated Packages Synopsis Important: wireshark security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for wireshark is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a computer network. Security Fix(es): wireshark: Heap-based Buffer Overflow in Wireshark (CVE-2026-5405) wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark (CVE-2026-5656) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2464273 - CVE-2026-5405 wireshark: Heap-based Buffer Overflow in Wireshark BZ - 2464276 - CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark CVEs CVE-2026-5405 CVE-2026-5656 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 x86_64 wireshark-4.4.2-10.el10_2.x86_64.rpm SHA-256: 46462741e789de94f81932ef6a68a18b64c93d544aacdd3e6e7abdc618ffdecd wireshark-cli-4.4.2-10.el10_2.x86_64.rpm SHA-256: 8cd0f86a1a72bb11c08f2960de8e307a0f0f21d755c646dd04215d9f7388517f wireshark-cli-debuginfo-4.4.2-10.el10_2.x86_64.rpm SHA-256: e439a8c0c6c5b0788ae2cd4959f0854857cc744e1bb5690e95ebee36beacb73a wireshark-debuginfo-4.4.2-10.el10_2.x86_64.rpm SHA-256: e4183bbfdd2f0a1fc057c22bb13bdb4087070b38dfc5ac750336ce13e48196ac wireshark-debugsource-4.4.2-10.el10_2.x86_64.rpm SHA-256: 2653fddb8f9a2e7cf1d3693802212e0d86526fb4792532e574a129bfa253c7e4 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 x86_64 wireshark-4.4.2-10.el10_2.x86_64.rpm SHA-256: 46462741e789de94f81932ef6a68a18b64c93d544aacdd3e6e7abdc618ffdecd wireshark-cli-4.4.2-10.el10_2.x86_64.rpm SHA-256: 8cd0f86a1a72bb11c08f2960de8e307a0f0f21d755c646dd04215d9f7388517f wireshark-cli-debuginfo-4.4.2-10.el10_2.x86_64.rpm SHA-256: e439a8c0c6c5b0788ae2cd4959f0854857cc744e1bb5690e95ebee36beacb73a wireshark-debuginfo-4.4.2-10.el10_2.x86_64.rpm SHA-256: e4183bbfdd2f0a1fc057c22bb13bdb4087070b38dfc5ac750336ce13e48196ac wireshark-debugsource-4.4.2-10.el10_2.x86_64.rpm SHA-256: 2653fddb8f9a2e7cf1d3693802212e0d86526fb4792532e574a129bfa253c7e4 Red Hat Enterprise Linux for IBM z Systems 10 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 s390x wireshark-4.4.2-10.el10_2.s390x.rpm SHA-256: edf0ee2e6964344692308e98336a49ee478323fbdddb24e0b3587c585a9458e4 wireshark-cli-4.4.2-10.el10_2.s390x.rpm SHA-256: 8da74e31c4290cb9d9f5a5cb4ce8907987d72cec854b01759d9a6f91fa62d551 wireshark-cli-debuginfo-4.4.2-10.el10_2.s390x.rpm SHA-256: 98192eff5120c0803937afb09e729a2cc94a45c1ca29c8be2dac786a55eaea1e wireshark-debuginfo-4.4.2-10.el10_2.s390x.rpm SHA-256: 2e13a08af64e747f548eb589c64b5982ccb30eafdd5870f82104f4937793741e wireshark-debugsource-4.4.2-10.el10_2.s390x.rpm SHA-256: 72685884e5bf0c48b80bbf23568fafbd70b6d0fa6c2c28ce22e8183f4ef89ab2 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 s390x wireshark-4.4.2-10.el10_2.s390x.rpm SHA-256: edf0ee2e6964344692308e98336a49ee478323fbdddb24e0b3587c585a9458e4 wireshark-cli-4.4.2-10.el10_2.s390x.rpm SHA-256: 8da74e31c4290cb9d9f5a5cb4ce8907987d72cec854b01759d9a6f91fa62d551 wireshark-cli-debuginfo-4.4.2-10.el10_2.s390x.rpm SHA-256: 98192eff5120c0803937afb09e729a2cc94a45c1ca29c8be2dac786a55eaea1e wireshark-debuginfo-4.4.2-10.el10_2.s390x.rpm SHA-256: 2e13a08af64e747f548eb589c64b5982ccb30eafdd5870f82104f4937793741e wireshark-debugsource-4.4.2-10.el10_2.s390x.rpm SHA-256: 72685884e5bf0c48b80bbf23568fafbd70b6d0fa6c2c28ce22e8183f4ef89ab2 Red Hat Enterprise Linux for Power, little endian 10 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 ppc64le wireshark-4.4.2-10.el10_2.ppc64le.rpm SHA-256: bfb5984524a207f999116846ab759587cc7ba852b48adae8285733fcc6fe2e2f wireshark-cli-4.4.2-10.el10_2.ppc64le.rpm SHA-256: 551fd56acdb84a5f93215f74893aab281956ac744f49a95862ca8c5f501729dd wireshark-cli-debuginfo-4.4.2-10.el10_2.ppc64le.rpm SHA-256: c8713f959404a101d4c182ce835e16265444bca7087204e2b52087d9fe0cc9ec wireshark-debuginfo-4.4.2-10.el10_2.ppc64le.rpm SHA-256: f996886ea63010d23f24ff4826271d97758d4baf01647e7537824f1d59af141a wireshark-debugsource-4.4.2-10.el10_2.ppc64le.rpm SHA-256: 8775c77b7a26bdba81883b2cae17161e7e79409dd00d8ddf8d2961d521dffd8f Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 ppc64le wireshark-4.4.2-10.el10_2.ppc64le.rpm SHA-256: bfb5984524a207f999116846ab759587cc7ba852b48adae8285733fcc6fe2e2f wireshark-cli-4.4.2-10.el10_2.ppc64le.rpm SHA-256: 551fd56acdb84a5f93215f74893aab281956ac744f49a95862ca8c5f501729dd wireshark-cli-debuginfo-4.4.2-10.el10_2.ppc64le.rpm SHA-256: c8713f959404a101d4c182ce835e16265444bca7087204e2b52087d9fe0cc9ec wireshark-debuginfo-4.4.2-10.el10_2.ppc64le.rpm SHA-256: f996886ea63010d23f24ff4826271d97758d4baf01647e7537824f1d59af141a wireshark-debugsource-4.4.2-10.el10_2.ppc64le.rpm SHA-256: 8775c77b7a26bdba81883b2cae17161e7e79409dd00d8ddf8d2961d521dffd8f Red Hat Enterprise Linux for ARM 64 10 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 aarch64 wireshark-4.4.2-10.el10_2.aarch64.rpm SHA-256: b483b0dff85cc362901a5bf0150cb8e94e6f57ae73da1180e06a86bbc85ec29c wireshark-cli-4.4.2-10.el10_2.aarch64.rpm SHA-256: cec538c7d6a1f2c9a74f53688a67c7b5ee895e1d551e4b02a88302bb94807ea8 wireshark-cli-debuginfo-4.4.2-10.el10_2.aarch64.rpm SHA-256: 9f599c1263d60f295a332afd286c8e50a36c6206cf8151bfc56935622e36ec2f wireshark-debuginfo-4.4.2-10.el10_2.aarch64.rpm SHA-256: 038d5f62d8a55dc7342c3c456d777b4185c410931f2cc24dfce09aca3c6a0a72 wireshark-debugsource-4.4.2-10.el10_2.aarch64.rpm SHA-256: 5caaf58b153e301c0812855fcce96be6ebcc8490425ed467966fb8dc4cb35299 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM wireshark-4.4.2-10.el10_2.src.rpm SHA-256: 5112f4a68092a223f44fe872a900bbb12c4ca593f39d4b24f429d5889d05f4c8 aarch64 wireshark-4.4.2-10.el10_2.aarch64.rpm SHA-256: b483b0dff85cc362901a5bf0150cb8e94e6f57ae73da1180e06a86bbc85ec29c wireshark-cli-4.4.2-10.el10_2.aarch64.rpm SHA-256: cec538c7d6a1f2c9a74f53688a67c7b5ee895e1d551e4b02a88302bb94807ea8 wireshark-cli-debuginfo-4.4.2-10.el10_2.aarch64.rpm SHA-256: 9f599c1263d60f295a332afd286c8e50a36c6206cf8151bfc56935622e36ec2f wireshark-debuginfo-4.4.2-10.el10_2.aarch64.rpm SHA-256: 038d5f62d8a55dc7342c3c456d777b4185c410931f2cc24dfce09aca3c6a0a72 wireshark-debugsource-4.4.2-10.el10_2.aarch64.rpm SHA-256: 5caaf58b153e301c0812855fcce96be6ebcc8490425ed467966fb8dc4cb35299 Red Hat CodeReady Linux Builder for x86_64 10 SRPM x86_64 wireshark-cli-debuginfo-4.4.2-10.el10_2.x86_64.rpm SHA-256: e439a8c0c6c5b0788ae2cd4959f0854857cc744e1bb5690e95ebee36beacb73a wireshark-debuginfo-4.4.2-10.el10_2.x86_64.rpm SHA-256: e4183
This Red Hat security advisory addresses two high-severity vulnerabilities in Wireshark: a heap-based buffer overflow (CVE-2026-5405, CVSS 7.8) and a path traversal flaw (CVE-2026-5656, CVSS 7.0). The affected versions are Wireshark 4.4.0 through 4.4.14 and 4.6.0 through 4.6.4. The vulnerabilities are fixed by upgrading to Wireshark versions 4.4.15 or 4.6.5.