CVE-2026-19695
PoC massStack-based buffer overflow in Wireshark Gammu DCT3 trace parser causes DoS
CVE-2026-19695 is a stack-based buffer overflow (CWE-121) in the Gammu DCT3 trace file parser of Wireshark, affecting versions 4.6.0 through 4.6.7. It is triggered when Wireshark parses a malformed or maliciously crafted Gammu DCT3 trace file — a debug trace format produced by the Gammu tool for Nokia DCT3 phones — and the CVSS vector indicates a local attack vector requiring user interaction, i.e., the user must open the crafted file. An attacker who gets a user to open such a file gains denial of service only: the parser crashes the application (high availability impact) with no confidentiality or integrity impact per the CVSS score. Any user running Wireshark 4.6.0 through 4.6.7 is affected, though because Gammu DCT3 traces are an obscure format, practical risk is concentrated among analysts who actually open such trace files. There is no evidence of in-the-wild exploitation: the issue is not in CISA KEV, EPSS is only 0.1% (2nd percentile), and the sole public reference is the upstream Wireshark bug report (GitLab work item 21475).
What to do: Upgrade Wireshark to the latest 4.6-series maintenance release (any version newer than 4.6.7), which contains the parser fix. Until patched, avoid opening untrusted Gammu DCT3 trace files with Wireshark and check whether any analysts regularly process such trace files. Given the low EPSS score, absence from KEV, and denial-of-service-only impact, this can be handled through routine patching cycles.
| Wireshark | 4.6.0 through 4.6.7 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.