ALAS2-2026-3208


Amazon Linux 2 Security Advisory: ALAS2-2026-3208
Advisory Released Date: 2026-03-19
Advisory Updated Date: 2026-03-19
Severity: Medium

Issue Overview:

ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file (CVE-2024-11596)

Memory handling issue in editcap could cause denial of service via crafted capture file (CVE-2024-4853)

MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service (CVE-2025-13946)

Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or crafted capture file (CVE-2025-5601)


Affected Packages:

wireshark


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update wireshark or yum update --advisory ALAS2-2026-3208 to update your system.

New Packages:
aarch64:
    wireshark-2.6.2-15.amzn2.0.10.aarch64
    wireshark-cli-2.6.2-15.amzn2.0.10.aarch64
    wireshark-devel-2.6.2-15.amzn2.0.10.aarch64
    wireshark-debuginfo-2.6.2-15.amzn2.0.10.aarch64

i686:
    wireshark-2.6.2-15.amzn2.0.10.i686
    wireshark-cli-2.6.2-15.amzn2.0.10.i686
    wireshark-devel-2.6.2-15.amzn2.0.10.i686
    wireshark-debuginfo-2.6.2-15.amzn2.0.10.i686

src:
    wireshark-2.6.2-15.amzn2.0.10.src

x86_64:
    wireshark-2.6.2-15.amzn2.0.10.x86_64
    wireshark-cli-2.6.2-15.amzn2.0.10.x86_64
    wireshark-devel-2.6.2-15.amzn2.0.10.x86_64
    wireshark-debuginfo-2.6.2-15.amzn2.0.10.x86_64