ZeroHour

CVE-2026-76920

PoC mass

Out-of-bounds write in Wireshark 3GPP phone log parser causes DoS crash

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

Wireshark contains an out-of-bounds write (CWE-787) in its 3GPP phone log file parser that crashes the application when parsing a malformed file. The flaw is triggered locally (AV:L) and requires user interaction (UI:R): a user must open a crafted 3GPP phone log file in an affected Wireshark version. The impact is denial of service - the CVSS vector shows high availability impact with no confidentiality or integrity impact. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected. Exploitation is not currently known in the wild (not in CISA KEV, EPSS ~0.1%), but a public PoC/reference exists in the Wireshark GitLab tracker (work item 21454).

What to do: Upgrade Wireshark to a release newer than the affected ranges - later than 4.6.7 on the 4.6 branch or later than 4.4.18 on the 4.4 branch - per the project's advisory (GitLab work item 21454). Until patched, avoid opening 3GPP phone log files from untrusted sources in Wireshark, and check whether analysts or tooling in your environment process such files.

Affected
wireshark4.6.0 through 4.6.7
wireshark4.4.0 through 4.4.18
Estimated exposure
massmillions of installs potentially affected (Wireshark's large installed base on its two current branches), though only users opening untrusted 3GPP phone log… — Wireshark is a free, ubiquitous network protocol analyzer with a multi-million-user installed base across its actively maintained 4.4 and 4.6 branches, but the local, user-interaction-required attack path makes actual exposure far narrower…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.