ZeroHour

CVE-2026-76889

PoC mass

Heap-based buffer overflow in Wireshark UMTS FP dissector enables DoS crash

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-76889 is a heap-based buffer overflow (CWE-122) in the UMTS FP protocol dissector of Wireshark, affecting releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when the dissector processes maliciously crafted or malformed UMTS FP packet data, which can occur when a user opens a crafted capture file or when such packets are captured and dissected live; the CVSS user-interaction requirement (UI:R) reflects this. An attacker gains denial of service only: the crash takes down the analysis session (Wireshark GUI or tshark), with no confidentiality or integrity impact and no indication of code execution. Anyone running the affected Wireshark branches — including analysts inspecting telecom/mobile-core captures with UMTS FP traffic — is affected. Exploitation in the wild is not known; the flaw carries an EPSS probability of about 0.1% (1st percentile), is not in CISA KEV, and is documented publicly in a Wireshark GitLab issue (work item 21413).

What to do: Upgrade Wireshark to the latest maintenance release of the 4.6 branch (newer than 4.6.7) or the 4.4 branch (newer than 4.4.18), which contain the fix. As an interim mitigation, disable the UMTS FP dissector via Analyze > Enabled Protocols and treat untrusted capture files or untrusted live-capture sources with caution until updated; also update any embedded tooling (e.g., tshark-based automation) that uses the same dissector engine.

Affected
Wireshark4.6.0 through 4.6.7
Wireshark4.4.0 through 4.4.18
Estimated exposure
mass≈ millions of desktop installations run Wireshark, though practical exposure is limited to the subset dissecting UMTS FP traffic — Wireshark is the de facto standard open-source packet analyzer with millions of users, and the affected versions span both currently maintained release branches, so installed base is very large even though the UMTS FP trigger path is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.