ZeroHour

CVE-2026-76879

PoC mass

Stack-based Buffer Overflow DoS in Wireshark C12.22 Dissector

CVSS 3.1
7.5 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-76879 is a stack-based buffer overflow (CWE-121) in the C12.22 protocol dissector of Wireshark, the parser for the ANSI C12.22 utility-metering protocol. An attacker triggers it by getting an affected Wireshark build to dissect a malformed C12.22 packet, either from live traffic during a capture or from a crafted capture file processed by non-interactive tooling; the resulting crash causes denial of service with no confidentiality or integrity impact (CVSS v3.1 7.5, AV:N/AC:L/PR:N/UI:N with high availability impact). Everyone running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 is affected, including GUI users and headless tshark-based monitoring or capture-parsing pipelines. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS puts the 30-day exploitation probability at 0.3% (19th percentile), and the only public reference is a PoC issue in the Wireshark tracker (GitLab work item 21480).

What to do: Upgrade Wireshark to a release later than 4.6.7 on the 4.6 branch or later than 4.4.18 on the 4.4 branch, and confirm the fixed versions in the vendor advisory (GitLab work item 21480). As interim mitigation, disable the C12.22 dissector (Analyze > Enabled Protocols, or tshark's --disable-protocol option) when capturing on untrusted networks or parsing untrusted capture files, and audit any automated tshark pipelines that process untrusted input.

Affected
Wireshark4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
Estimated exposure
mass≈ millions of active installations (estimated) — Estimate based on Wireshark being one of the most widely deployed open-source packet analyzers (tens of millions of cumulative downloads and common bundling in network/security tooling) with the affected 4.6.x and 4.4.x lines being its…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.