CVE-2026-76884
PoC massBuffer Over-Read in Wireshark ERF File Parser Enables DoS Crashes
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a buffer over-read (CWE-126) in the parser for ERF (Extensible Record Format) capture files. The flaw is triggered when a user opens or processes a malformed or specially crafted ERF file, which crashes the application. The impact is availability only — there is no evidence of code execution or data disclosure, matching the CVSS score of 6.5 with high availability impact and no confidentiality or integrity impact. All users running the affected Wireshark releases who handle ERF captures are exposed, with user interaction required to trigger the crash. Exploitation has not been reported in the wild; a public proof-of-concept issue exists on the Wireshark GitLab tracker, and EPSS puts 30-day exploitation probability at just 0.2%.
What to do: Update Wireshark to a release newer than 4.6.7 and 4.4.18 (the current patched builds in each branch) on any host that processes capture files. As an interim mitigation, avoid opening untrusted or third-party ERF capture files with affected versions and have analysts use patched installations or conversion tooling instead. Verify the installed version via Help > About Wireshark or 'tshark --version' across analyst workstations and automated capture-processing hosts.
| wireshark | 4.6.0 through 4.6.7 |
| wireshark | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.