CVE-2026-76919
PoC massUninitialized-variable crash in Wireshark ESS dissector enables denial of service
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a use of an uninitialized variable (CWE-457) in the ESS protocol dissector that can crash the application. The flaw is triggered when affected builds process network traffic or capture data through the ESS dissector, causing a crash that halts the analysis tool. A successful attack yields denial of service only; the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) indicates no confidentiality or integrity impact and no privileges required. Anyone running the affected Wireshark releases, particularly users capturing or dissecting untrusted network traffic or capture files, is affected. A public proof-of-concept reference exists on the Wireshark GitLab tracker (work item 21467), but the flaw is not in CISA's KEV catalog and EPSS estimates only a ~0.3% probability of exploitation in the next 30 days, indicating no confirmed in-the-wild exploitation.
What to do: Upgrade Wireshark beyond the affected ranges, i.e., to the latest maintenance releases of the 4.6.x and 4.4.x branches (any release newer than 4.6.7/4.4.18), and track the referenced GitLab work item 21467 for fix details. Until patched, disable the ESS dissector via Wireshark's Enabled Protocols settings or avoid dissecting untrusted traffic and capture files. Defenders should prioritize hosts that analyze traffic from untrusted networks or third-party pcap files.
| Wireshark | 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-457
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.