CVE-2026-76889
PoC massHeap-based buffer overflow in Wireshark UMTS FP dissector enables DoS crash
CVE-2026-76889 is a heap-based buffer overflow (CWE-122) in the UMTS FP protocol dissector of Wireshark, affecting releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when the dissector processes maliciously crafted or malformed UMTS FP packet data, which can occur when a user opens a crafted capture file or when such packets are captured and dissected live; the CVSS user-interaction requirement (UI:R) reflects this. An attacker gains denial of service only: the crash takes down the analysis session (Wireshark GUI or tshark), with no confidentiality or integrity impact and no indication of code execution. Anyone running the affected Wireshark branches — including analysts inspecting telecom/mobile-core captures with UMTS FP traffic — is affected. Exploitation in the wild is not known; the flaw carries an EPSS probability of about 0.1% (1st percentile), is not in CISA KEV, and is documented publicly in a Wireshark GitLab issue (work item 21413).
What to do: Upgrade Wireshark to the latest maintenance release of the 4.6 branch (newer than 4.6.7) or the 4.4 branch (newer than 4.4.18), which contain the fix. As an interim mitigation, disable the UMTS FP dissector via Analyze > Enabled Protocols and treat untrusted capture files or untrusted live-capture sources with caution until updated; also update any embedded tooling (e.g., tshark-based automation) that uses the same dissector engine.
| Wireshark | 4.6.0 through 4.6.7 |
| Wireshark | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.