ZeroHour

CVE-2026-76886

PoC ×2mass

Heap-based buffer overflow in Wireshark C12.22 dissector enables denial of service

CVSS 3.1
9.8 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-76886 is a heap-based buffer overflow (CWE-122) in the C12.22 protocol dissector of the Wireshark network protocol analyzer, affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when a vulnerable Wireshark or tshark instance dissects a maliciously crafted C12.22 packet, whether from live network traffic during a capture or from an attacker-supplied capture file. An attacker who can get such a packet into a capture session gains denial of service, crashing the analyzer and interrupting capture/analysis; the CVE is rated 9.8 (critical) under CVSS 3.1, although the described impact is limited to a dissector crash. Anyone running the listed Wireshark versions is affected, particularly analysts capturing on networks where third parties can inject traffic or processing untrusted capture files. Exploitation has not been reported in the wild; the bug is tracked in public GitLab issues, is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade Wireshark to the first release after 4.6.7 in the 4.6 branch or after 4.4.18 in the 4.4 branch as soon as the patch releases are available. Until then, disable the C12.22 dissector via Analyze > Enabled Protocols, and avoid running automated tshark/capture jobs or file-formatting analysis on untrusted traffic or capture files from untrusted sources.

Affected
wireshark4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
Estimated exposure
massmillions of Wireshark installations on the 4.4.x/4.6.x branches, though only hosts dissecting attacker-controlled C12.22 traffic are realistically triggerable — Wireshark is the dominant open-source packet analyzer with tens of millions of cumulative downloads and a large enterprise and analyst install base, and the 4.4 and 4.6 lines are its current stable release branches, but the flaw only fires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.