ZeroHour

CVE-2026-76921

PoC ×2mass

Use-after-free in Wireshark CMS dissector causes denial-of-service crash

CVSS 3.1
5.5 medium
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-76921 is a use-after-free flaw (CWE-416) in Wireshark's CMS protocol dissector that can crash the application. It is triggered when Wireshark dissects packets containing malformed CMS data, for example when an analyst opens a crafted capture file or when live traffic is being dissected; the CVSS local vector with user-interaction requirement reflects this file-open/dissection scenario. A successful attack results in denial of service only (high availability impact, no confidentiality or integrity impact), crashing the Wireshark session. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected. No confirmed in-the-wild exploitation is reported: the flaw has public bug-tracker references, a low EPSS probability of about 0.1% within 30 days, and it is not in CISA's KEV catalog.

What to do: Upgrade Wireshark to the first releases after the affected ranges - 4.6.8 or later on the 4.6 branch and 4.4.19 or later on the 4.4 branch, or any newer stable release. As an interim mitigation, avoid opening untrusted capture files and stop dissecting untrusted CMS traffic, or disable the CMS dissector via Analyze > Enabled Protocols. Check your installed version (Help > About Wireshark) against the affected ranges above.

Affected
wireshark4.6.0 to 4.6.7
wireshark4.4.0 to 4.4.18
Estimated exposure
massmillions of desktop installations (Wireshark is the de facto standard packet analyzer; only users on the 4.6.0-4.6.7 and 4.4.0-4.4.18 branches are affected) — Wireshark is among the most widely deployed desktop network analyzers with a user base in the millions, so the potentially affected install base is very large, though actual risk is limited to users of the affected branches who open…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.