CVE-2026-76924
PoC massOut-of-bounds read in Wireshark Kerberos dissector enables DoS crash
An out-of-bounds read (CWE-125) in the Kerberos protocol dissector of Wireshark can crash the application, resulting in a denial of service. The flaw is triggered when the dissector processes crafted Kerberos packets — typically when a user opens a malicious capture file or dissects such traffic during a capture, which matches the CVSS local-vector and user-interaction-required scoring. The impact is availability only: a crash interrupts the analysis or capture session, with no code execution, data theft, or integrity loss. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected, including automated or headless use of the tooling that processes untrusted captures. Exploitation has not been observed in the wild; the issue is tracked publicly in Wireshark's issue tracker (work item 21449), it is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within 30 days.
What to do: Upgrade Wireshark to the first release after 4.6.7 on the 4.6 branch or after 4.4.18 on the 4.4 branch, and verify installed versions via Help → About Wireshark. As interim mitigation, avoid opening capture files from untrusted sources and disable the Kerberos dissector via Analyze → Enabled Protocols when dissecting untrusted traffic; update any automation that feeds untrusted captures to the tooling. Given the local attack vector, user-interaction requirement, and low EPSS (0.1%), this is a low-priority patch except where Wireshark routinely handles untrusted captures.
| wireshark | 4.6.0 through 4.6.7 |
| wireshark | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.