ZeroHour

CVE-2026-19695

PoC mass

Stack-based buffer overflow in Wireshark Gammu DCT3 trace parser causes DoS

CVSS 3.1
5.5 medium
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-19695 is a stack-based buffer overflow (CWE-121) in the Gammu DCT3 trace file parser of Wireshark, affecting versions 4.6.0 through 4.6.7. It is triggered when Wireshark parses a malformed or maliciously crafted Gammu DCT3 trace file — a debug trace format produced by the Gammu tool for Nokia DCT3 phones — and the CVSS vector indicates a local attack vector requiring user interaction, i.e., the user must open the crafted file. An attacker who gets a user to open such a file gains denial of service only: the parser crashes the application (high availability impact) with no confidentiality or integrity impact per the CVSS score. Any user running Wireshark 4.6.0 through 4.6.7 is affected, though because Gammu DCT3 traces are an obscure format, practical risk is concentrated among analysts who actually open such trace files. There is no evidence of in-the-wild exploitation: the issue is not in CISA KEV, EPSS is only 0.1% (2nd percentile), and the sole public reference is the upstream Wireshark bug report (GitLab work item 21475).

What to do: Upgrade Wireshark to the latest 4.6-series maintenance release (any version newer than 4.6.7), which contains the parser fix. Until patched, avoid opening untrusted Gammu DCT3 trace files with Wireshark and check whether any analysts regularly process such trace files. Given the low EPSS score, absence from KEV, and denial-of-service-only impact, this can be handled through routine patching cycles.

Affected
Wireshark4.6.0 through 4.6.7 (inclusive)
Estimated exposure
mass~1M+ users (Wireshark's global install base); practical trigger limited to users opening Gammu DCT3 trace files — Wireshark is the de facto standard open-source packet analyzer with a user base in the millions and 4.6.x is its current release branch, but exploitation additionally requires a user to open a niche Gammu DCT3 trace file, so day-to-day…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.