CVE-2026-76885
PoC massBuffer over-read in Wireshark Tektronix K12xx parser enables DoS crash
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a buffer over-read (CWE-126) in the Tektronix K12xx capture-file parser. An attacker triggers the flaw by getting a user to open a malformed or maliciously crafted Tektronix K12xx capture file, matching the CVSS vector (AV:N/AC:L/PR:N/UI:R), which describes a network-reachable attack requiring user interaction. The result is a crash during file parsing, i.e., a denial of service with high availability impact but no confidentiality or integrity impact per the CVSS scoring. Anyone running the affected 4.4.x or 4.6.x releases and opening K12xx-format capture files is affected; the flaw is client-side, so servers and appliances are largely unaffected. The bug is tracked publicly in the Wireshark issue tracker, but it is not in CISA KEV and EPSS assigns only a 0.2% probability of exploitation in the next 30 days, so no in-the-wild exploitation is known.
What to do: Upgrade to a Wireshark release beyond the affected ranges — 4.6.8 or later, or 4.4.19 or later on the 4.4 maintenance branch. Until patched, avoid opening untrusted or unsolicited Tektronix K12xx capture files, and note the impact is limited to a parser crash, so restarting the application restores service. Verify deployed versions via Wireshark's About dialog or your software inventory.
| wireshark | 4.6.0 to 4.6.7 |
| wireshark | 4.4.0 to 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.