ZeroHour

CVE-2026-76890

PoC mass

Use-after-free crash in Wireshark's sharkd daemon enables remote denial of service

CVSS 3.1
6.5 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

A use-after-free flaw (CWE-825, expired pointer dereference) in Wireshark's sharkd daemon can crash the process when it processes crafted capture data. sharkd is typically triggered to analyze attacker-influenced packet or capture-file input, which the CVSS vector reflects as network access combined with user interaction (AV:N/UI:R). A successful trigger only yields denial of service: the daemon dereferences a freed pointer and crashes, with no confidentiality or integrity impact (6.5 medium, availability only). Affected users are anyone running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18, with the greatest practical risk in deployments where sharkd runs as a shared or network-facing analysis service handling untrusted files. There is no known in-the-wild exploitation; one public proof-of-concept reference exists in the upstream Wireshark tracker (GitLab work item 21399), and EPSS estimates only about 0.2 percent exploitation probability over 30 days, with the CVE not in CISA KEV.

What to do: Upgrade Wireshark to a patch release newer than 4.6.7 on the 4.6 branch or 4.4.18 on the 4.4 branch. Until patched, avoid having sharkd analyze untrusted capture files, restrict sharkd access to trusted users and networks, and monitor the daemon for crash/restart events. Track the upstream issue (GitLab work item 21399) for fix status.

Affected
wireshark (sharkd daemon, 4.6 branch)4.6.0 through 4.6.7
wireshark (sharkd daemon, 4.4 branch)4.4.0 through 4.4.18
Estimated exposure
massmillions of Wireshark installations ship sharkd; directly exposed sharkd services are plausibly a much smaller subset — Wireshark's long-standing user base is in the millions and the sharkd daemon ships with every affected release, though only deployments where sharkd processes untrusted capture data are practically reachable, making precise counts unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-825
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.