ZeroHour

CVE-2026-76926

PoC moderate

Reachable assertion crash in Wireshark BUSMASTER file parser enables DoS

CVSS 3.1
6.5 medium
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-76926 is a denial-of-service flaw in the BUSMASTER log file parser of Wireshark, where malformed input triggers a reachable assertion and abnormal program exit (CWE-617). It is triggered when a user on an affected version (4.6.0 to 4.6.7 or 4.4.0 to 4.4.18) opens or imports a crafted BUSMASTER log file, e.g., a malicious file delivered via email or a shared repository. The attacker impact is limited to availability per the CVSS score (C:N/I:N/A:H): the Wireshark session or batch parsing job crashes, with no code execution, data theft, or tampering. Anyone running the affected Wireshark releases is technically affected, but in practice only users who actually parse BUSMASTER (CAN-bus) log files are exposed. No in-the-wild exploitation is known; one public PoC/bug reference exists on Wireshark's GitLab tracker and EPSS is low at 0.2%.

What to do: Upgrade Wireshark to a patch release newer than the affected ranges — any version after 4.6.7 on the 4.6 branch or after 4.4.18 on the 4.4 branch — and check the referenced GitLab work item (21435) for fix confirmation. As an interim mitigation, do not open BUSMASTER log files from untrusted sources in Wireshark, and verify whether any automated tooling imports such files.

Affected
wireshark4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
Estimated exposure
moderatetens of thousands of users (the niche subset of Wireshark's multi-million-user install base that opens BUSMASTER CAN-bus log files on affected 4.4.x/4.6.x… — Wireshark has millions of users worldwide, but the vulnerable code path only executes when parsing the niche BUSMASTER log format (an automotive CAN-bus file type), so plausible exposure is limited to that subset of users on the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-617
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.