CVE-2026-19696
PoC moderateOut-of-bounds write in Wireshark IxVeriWave and Vector BLF parsers causes DoS
CVE-2026-19696 is an out-of-bounds write (CWE-787) in Wireshark's file parsers for Ixia IxVeriWave captures and Vector Informatik BLF (Bus Logging Format) files. It is triggered when a user opens a specially crafted or corrupted .vwf or .blf file in Wireshark 4.6.0 through 4.6.7 on Windows, causing the parser to crash the application; the local attack vector and required user interaction in the CVSS score confirm that opening a supplied file is the trigger. An attacker who can get a user to open such a file gains a denial of service only — Wireshark crashes and analysis is interrupted, but confidentiality and integrity are not affected (C:N/I:N/A:H), with no indication of code execution. Affected users are Windows installations of Wireshark 4.6.0–4.6.7 whose workflows involve IxVeriWave or BLF capture files, such as wireless LAN test teams and automotive/embedded bus analysis. Exploitation status: one public PoC/issue reference exists (Wireshark GitLab issue 21455), EPSS is low at 0.1% (2nd percentile), the flaw is not in CISA KEV, and there are no known reports of in-the-wild exploitation.
What to do: Upgrade Wireshark to any release after 4.6.7 (the next 4.6.x maintenance release or the current stable build) on Windows systems. Until patched, do not open untrusted or externally supplied .vwf (IxVeriWave) or .blf (Vector) capture files with 4.6.0–4.6.7 on Windows, or preview them on a non-Windows host instead. Check whether analysts routinely ingest BLF/VWF captures from partners or shared archives, since a crafted capture file delivered this way is the likely attack vector.
| Wireshark | 4.6.0 through 4.6.7 on Windows (Ixia IxVeriWave and Vector Informatik BLF file parsers) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.