CVE-2026-76890
PoC massUse-after-free crash in Wireshark's sharkd daemon enables remote denial of service
A use-after-free flaw (CWE-825, expired pointer dereference) in Wireshark's sharkd daemon can crash the process when it processes crafted capture data. sharkd is typically triggered to analyze attacker-influenced packet or capture-file input, which the CVSS vector reflects as network access combined with user interaction (AV:N/UI:R). A successful trigger only yields denial of service: the daemon dereferences a freed pointer and crashes, with no confidentiality or integrity impact (6.5 medium, availability only). Affected users are anyone running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18, with the greatest practical risk in deployments where sharkd runs as a shared or network-facing analysis service handling untrusted files. There is no known in-the-wild exploitation; one public proof-of-concept reference exists in the upstream Wireshark tracker (GitLab work item 21399), and EPSS estimates only about 0.2 percent exploitation probability over 30 days, with the CVE not in CISA KEV.
What to do: Upgrade Wireshark to a patch release newer than 4.6.7 on the 4.6 branch or 4.4.18 on the 4.4 branch. Until patched, avoid having sharkd analyze untrusted capture files, restrict sharkd access to trusted users and networks, and monitor the daemon for crash/restart events. Track the upstream issue (GitLab work item 21399) for fix status.
| wireshark (sharkd daemon, 4.6 branch) | 4.6.0 through 4.6.7 |
| wireshark (sharkd daemon, 4.4 branch) | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-825
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.