It was found that HTTP2 dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Upstream bug(s): https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14869 External References: https://www.wireshark.org/security/wnpa-sec-2018-41.html
Created wireshark tracking bugs for this issue: Affects: fedora-all [bug 1607334]
The wireshark versions shipped in Red Hat Enterprise Linux 6 and 7 do not have the HTTP2 dissector functionality. Thus, they are not affected by this issue.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 6 and 7 (versions 1.8.10 and 1.10.14, respectively).