CVE-2026-76918
PoC massHeap buffer overflow in Wireshark SSH dissector causes denial of service
A heap-based buffer overflow (CWE-122) in Wireshark's SSH protocol dissector can crash the application when it processes crafted SSH packet data, typically when an analyst opens a malicious capture file or dissects traffic containing malformed SSH packets. Successful exploitation results in denial of service only: the crash kills the capture or analysis session, with no confidentiality or integrity impact. Anyone running the affected releases - Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 - is exposed, and the CVSS vector (AV:L/UI:R) indicates the crash requires user interaction such as loading a capture or dissecting attacker-supplied SSH traffic. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS puts the 30-day exploitation probability at only 0.1% (1st percentile), and one public proof-of-concept/bug reference exists (GitLab issue 21465).
What to do: Upgrade to a Wireshark release newer than 4.6.7 on the 4.6 branch or newer than 4.4.18 on the 4.4 branch (the latest maintenance release of either series), including updated packages supplied by your OS vendor. As an interim mitigation, disable SSH dissection via Analyze > Enabled Protocols (uncheck SSH) or avoid opening untrusted captures and live SSH traffic in the affected versions. Check installed versions with wireshark --version or tshark --version before and after patching.
| Wireshark | 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.