CVE-2026-76921
PoC ×2massUse-after-free in Wireshark CMS dissector causes denial-of-service crash
CVE-2026-76921 is a use-after-free flaw (CWE-416) in Wireshark's CMS protocol dissector that can crash the application. It is triggered when Wireshark dissects packets containing malformed CMS data, for example when an analyst opens a crafted capture file or when live traffic is being dissected; the CVSS local vector with user-interaction requirement reflects this file-open/dissection scenario. A successful attack results in denial of service only (high availability impact, no confidentiality or integrity impact), crashing the Wireshark session. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected. No confirmed in-the-wild exploitation is reported: the flaw has public bug-tracker references, a low EPSS probability of about 0.1% within 30 days, and it is not in CISA's KEV catalog.
What to do: Upgrade Wireshark to the first releases after the affected ranges - 4.6.8 or later on the 4.6 branch and 4.4.19 or later on the 4.4 branch, or any newer stable release. As an interim mitigation, avoid opening untrusted capture files and stop dissecting untrusted CMS traffic, or disable the CMS dissector via Analyze > Enabled Protocols. Check your installed version (Help > About Wireshark) against the affected ranges above.
| wireshark | 4.6.0 to 4.6.7 |
| wireshark | 4.4.0 to 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.