ZeroHour

CVE-2026-19694

PoC mass

Heap buffer overflow in Wireshark TTX Logger parser causes crash DoS

CVSS 3.1
5.5 medium
EPSS
<1%p3
Published
()
Modified
AI analysis

Wireshark versions 4.6.0 through 4.6.7 contain a heap-based buffer overflow (CWE-122) in the TTX Logger file parser, the component used to read TTX Logger capture files. The flaw is triggered when the parser processes a crafted or malformed TTX Logger file, and the CVSS vector (local attack vector, user interaction required) means an attacker needs a local user to open the malicious file. Successful exploitation crashes the application, producing a denial of service with no confidentiality or integrity impact. Anyone running Wireshark 4.6.0 through 4.6.7 is affected, especially users who open capture files obtained from untrusted sources. No in-the-wild exploitation is known: the issue is documented with a public PoC reference on the Wireshark GitLab tracker, EPSS is 0.1% (3rd percentile), and it is not in CISA KEV.

What to do: Check the installed Wireshark version and upgrade to a release newer than 4.6.7 when available from wireshark.org. As an interim mitigation, do not open TTX Logger capture files from untrusted or unexpected sources with affected 4.6.x builds; the flaw only causes a crash, so risk is limited to availability.

Affected
Wireshark4.6.0 through 4.6.7
Estimated exposure
massmillions of desktop installations (Wireshark is the de facto standard free packet analyzer, and 4.6.x is the current release branch) — Estimated from Wireshark's very large global user base (cumulative downloads in the tens of millions) with the 4.6.x branch as the current stable release, tempered by the fact that exploitation requires a local user to open a malicious TTX…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.