ZeroHour

CVE-2026-76918

PoC mass

Heap buffer overflow in Wireshark SSH dissector causes denial of service

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

A heap-based buffer overflow (CWE-122) in Wireshark's SSH protocol dissector can crash the application when it processes crafted SSH packet data, typically when an analyst opens a malicious capture file or dissects traffic containing malformed SSH packets. Successful exploitation results in denial of service only: the crash kills the capture or analysis session, with no confidentiality or integrity impact. Anyone running the affected releases - Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 - is exposed, and the CVSS vector (AV:L/UI:R) indicates the crash requires user interaction such as loading a capture or dissecting attacker-supplied SSH traffic. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS puts the 30-day exploitation probability at only 0.1% (1st percentile), and one public proof-of-concept/bug reference exists (GitLab issue 21465).

What to do: Upgrade to a Wireshark release newer than 4.6.7 on the 4.6 branch or newer than 4.4.18 on the 4.4 branch (the latest maintenance release of either series), including updated packages supplied by your OS vendor. As an interim mitigation, disable SSH dissection via Analyze > Enabled Protocols (uncheck SSH) or avoid opening untrusted captures and live SSH traffic in the affected versions. Check installed versions with wireshark --version or tshark --version before and after patching.

Affected
Wireshark4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
Estimated exposure
massmillions of users/installations worldwide on the affected 4.4.x/4.6.x branches — Wireshark is the de facto open-source packet analyzer with cumulative downloads in the hundreds of millions and inclusion in major Linux distribution repositories, so a multi-million install base is plausible, and the current 4.4.x/4.6.x…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.