ALAS2023-2026-2117


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2117
Advisory Released Date: 2026-08-31
Advisory Updated Date: 2026-08-31
Severity: Important

Issue Overview:

TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service (CVE-2026-19694)

Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service (CVE-2026-19695)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76879)

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76880)

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76881)

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76882)

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76883)

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76884)

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76885)

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76886)

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76887)

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76888)

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76889)

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76890)

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76891)

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76917)

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76918)

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76919)

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76920)

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76921)

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76922)

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76923)

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76924)

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76926)

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76927)

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76928)

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service (CVE-2026-76929)


Affected Packages:

wireshark


Issue Correction:
Run dnf update wireshark --releasever 2023.12.20260831 or dnf update --advisory ALAS2023-2026-2117 --releasever 2023.12.20260831 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    wireshark-cli-debuginfo-4.6.8-1.amzn2023.0.1.aarch64
    wireshark-cli-4.6.8-1.amzn2023.0.1.aarch64
    wireshark-devel-4.6.8-1.amzn2023.0.1.aarch64
    wireshark-debugsource-4.6.8-1.amzn2023.0.1.aarch64

src:
    wireshark-4.6.8-1.amzn2023.0.1.src

x86_64:
    wireshark-cli-debuginfo-4.6.8-1.amzn2023.0.1.x86_64
    wireshark-cli-4.6.8-1.amzn2023.0.1.x86_64
    wireshark-debugsource-4.6.8-1.amzn2023.0.1.x86_64
    wireshark-devel-4.6.8-1.amzn2023.0.1.x86_64