In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.

Attack vector:  Network
Severity:  Medium
CVSS Score:  5.0
CVSS Vector:  (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Patch:  patch