CVE-2026-76883
PoC massHeap-based buffer overflow in Wireshark Catapult DCT2000 parser causes DoS
CVE-2026-76883 is a heap-based buffer overflow (CWE-122) in the Catapult DCT2000 file parser of Wireshark, affecting releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when a user opens a crafted or corrupt Catapult DCT2000 capture file, with the CVSS vector (AV:L, UI:R) indicating a local, user-interaction-required attack rather than a network-triggered flaw. A successful exploit crashes the application, causing denial of service only; there is no confidentiality or integrity impact and the flaw is rated medium (CVSS 5.5). Anyone running Wireshark in the affected version ranges who handles capture files from this protocol is exposed, though Catapult DCT2000 is a specialized telecom diagnostic format, so practical exposure is limited to analysts who open such files. Exploitation is not known to be occurring in the wild: EPSS is 0.1%, the flaw is not in CISA KEV, and the only public reference is the Wireshark GitLab issue tracker item (work item 21427).
What to do: Update Wireshark to a release newer than the affected ranges — 4.6.8 or later on the 4.6 branch, or 4.4.19 or later on the 4.4 branch. Until patched, avoid opening untrusted Catapult DCT2000 capture files; check the installed version via Help > About Wireshark or tshark --version. This is a medium-severity local DoS with no known in-the-wild exploitation, so routine patching cadence is sufficient.
| Wireshark | 4.6.0 through 4.6.7 |
| Wireshark | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.