CVE-2026-76926
PoC moderateReachable assertion crash in Wireshark BUSMASTER file parser enables DoS
CVE-2026-76926 is a denial-of-service flaw in the BUSMASTER log file parser of Wireshark, where malformed input triggers a reachable assertion and abnormal program exit (CWE-617). It is triggered when a user on an affected version (4.6.0 to 4.6.7 or 4.4.0 to 4.4.18) opens or imports a crafted BUSMASTER log file, e.g., a malicious file delivered via email or a shared repository. The attacker impact is limited to availability per the CVSS score (C:N/I:N/A:H): the Wireshark session or batch parsing job crashes, with no code execution, data theft, or tampering. Anyone running the affected Wireshark releases is technically affected, but in practice only users who actually parse BUSMASTER (CAN-bus) log files are exposed. No in-the-wild exploitation is known; one public PoC/bug reference exists on Wireshark's GitLab tracker and EPSS is low at 0.2%.
What to do: Upgrade Wireshark to a patch release newer than the affected ranges — any version after 4.6.7 on the 4.6 branch or after 4.4.18 on the 4.4 branch — and check the referenced GitLab work item (21435) for fix confirmation. As an interim mitigation, do not open BUSMASTER log files from untrusted sources in Wireshark, and verify whether any automated tooling imports such files.
| wireshark | 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-617
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.