CVE-2026-76879
PoC massStack-based Buffer Overflow DoS in Wireshark C12.22 Dissector
CVE-2026-76879 is a stack-based buffer overflow (CWE-121) in the C12.22 protocol dissector of Wireshark, the parser for the ANSI C12.22 utility-metering protocol. An attacker triggers it by getting an affected Wireshark build to dissect a malformed C12.22 packet, either from live traffic during a capture or from a crafted capture file processed by non-interactive tooling; the resulting crash causes denial of service with no confidentiality or integrity impact (CVSS v3.1 7.5, AV:N/AC:L/PR:N/UI:N with high availability impact). Everyone running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 is affected, including GUI users and headless tshark-based monitoring or capture-parsing pipelines. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS puts the 30-day exploitation probability at 0.3% (19th percentile), and the only public reference is a PoC issue in the Wireshark tracker (GitLab work item 21480).
What to do: Upgrade Wireshark to a release later than 4.6.7 on the 4.6 branch or later than 4.4.18 on the 4.4 branch, and confirm the fixed versions in the vendor advisory (GitLab work item 21480). As interim mitigation, disable the C12.22 dissector (Analyze > Enabled Protocols, or tshark's --disable-protocol option) when capturing on untrusted networks or parsing untrusted capture files, and audit any automated tshark pipelines that process untrusted input.
| Wireshark | 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.