ZeroHour

CVE-2026-76884

PoC mass

Buffer Over-Read in Wireshark ERF File Parser Enables DoS Crashes

CVSS 3.1
6.5 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a buffer over-read (CWE-126) in the parser for ERF (Extensible Record Format) capture files. The flaw is triggered when a user opens or processes a malformed or specially crafted ERF file, which crashes the application. The impact is availability only — there is no evidence of code execution or data disclosure, matching the CVSS score of 6.5 with high availability impact and no confidentiality or integrity impact. All users running the affected Wireshark releases who handle ERF captures are exposed, with user interaction required to trigger the crash. Exploitation has not been reported in the wild; a public proof-of-concept issue exists on the Wireshark GitLab tracker, and EPSS puts 30-day exploitation probability at just 0.2%.

What to do: Update Wireshark to a release newer than 4.6.7 and 4.4.18 (the current patched builds in each branch) on any host that processes capture files. As an interim mitigation, avoid opening untrusted or third-party ERF capture files with affected versions and have analysts use patched installations or conversion tooling instead. Verify the installed version via Help > About Wireshark or 'tshark --version' across analyst workstations and automated capture-processing hosts.

Affected
wireshark4.6.0 through 4.6.7
wireshark4.4.0 through 4.4.18
Estimated exposure
masslikely over 1,000,000 users on affected 4.4.x/4.6.x builds (Wireshark has a global installed base in the millions and these are current release branches) — Wireshark is one of the most widely deployed network analyzers, with millions of users worldwide, and the affected 4.4 and 4.6 branches are recent maintained releases, so a large share of the user base plausibly runs a vulnerable build;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-126
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.