ZeroHour

CVE-2026-19696

PoC moderate

Out-of-bounds write in Wireshark IxVeriWave and Vector BLF parsers causes DoS

CVSS 3.1
5.5 medium
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-19696 is an out-of-bounds write (CWE-787) in Wireshark's file parsers for Ixia IxVeriWave captures and Vector Informatik BLF (Bus Logging Format) files. It is triggered when a user opens a specially crafted or corrupted .vwf or .blf file in Wireshark 4.6.0 through 4.6.7 on Windows, causing the parser to crash the application; the local attack vector and required user interaction in the CVSS score confirm that opening a supplied file is the trigger. An attacker who can get a user to open such a file gains a denial of service only — Wireshark crashes and analysis is interrupted, but confidentiality and integrity are not affected (C:N/I:N/A:H), with no indication of code execution. Affected users are Windows installations of Wireshark 4.6.0–4.6.7 whose workflows involve IxVeriWave or BLF capture files, such as wireless LAN test teams and automotive/embedded bus analysis. Exploitation status: one public PoC/issue reference exists (Wireshark GitLab issue 21455), EPSS is low at 0.1% (2nd percentile), the flaw is not in CISA KEV, and there are no known reports of in-the-wild exploitation.

What to do: Upgrade Wireshark to any release after 4.6.7 (the next 4.6.x maintenance release or the current stable build) on Windows systems. Until patched, do not open untrusted or externally supplied .vwf (IxVeriWave) or .blf (Vector) capture files with 4.6.0–4.6.7 on Windows, or preview them on a non-Windows host instead. Check whether analysts routinely ingest BLF/VWF captures from partners or shared archives, since a crafted capture file delivered this way is the likely attack vector.

Affected
Wireshark4.6.0 through 4.6.7 on Windows (Ixia IxVeriWave and Vector Informatik BLF file parsers)
Estimated exposure
moderate≈tens of thousands of users (out of Wireshark's multi-million install base) — Wireshark is installed millions of times worldwide, but this bug only affects Windows users on 4.6.0–4.6.7 who actually open IxVeriWave or Vector BLF files — a specialty subset (wireless test and automotive bus analysis) plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

Vendors
wireshark
Products
wireshark
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.