ZeroHour

CVE-2026-76927

PoC mass

Null pointer dereference in Wireshark H.245 dissector allows denial of service

CVSS 3.1
7.5 high
EPSS
<1%p5
Published
()
Modified
AI analysis

Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a null pointer dereference (CWE-476) in the H.245 protocol dissector, the component that decodes H.323 multimedia call-signaling traffic. The crash is triggered when the dissector processes crafted or malformed H.245 data, such as specially crafted packets sent across a network being monitored during a live capture or a malicious capture file being parsed. The impact is denial of service only: the Wireshark or tshark process crashes, with no confidentiality or integrity impact and no indication of code execution. Anyone running the affected releases is affected, with practical risk concentrated on analysts and monitoring hosts dissecting traffic containing H.245 (VoIP/video conferencing) flows. There is no confirmed in-the-wild exploitation: EPSS estimates roughly a 0.2% probability of exploitation within 30 days (5th percentile), the flaw is not in CISA KEV, and only one public PoC/issue reference (Wireshark GitLab work item) is available.

What to do: Upgrade Wireshark on affected hosts to a release newer than 4.6.7 on the 4.6 branch or newer than 4.4.18 on the 4.4 branch as soon as patched packages are available. As an interim mitigation, disable the H.245 dissector (Analyze > Enabled Protocols, or the equivalent tshark/disable-protocol setting) and avoid opening capture files from untrusted sources with affected versions. Track the referenced GitLab work item for the fixed releases and any additional details.

Affected
Wireshark4.6.0 through 4.6.7 (4.6 branch)
Wireshark4.4.0 through 4.4.18 (4.4 branch)
Estimated exposure
massmillions of Wireshark installations (multi-million user base), though only sessions dissecting H.245 traffic or opening untrusted captures are practically… — Wireshark is one of the most widely deployed open-source packet analyzers, with cumulative downloads in the tens of millions and an active user base in the millions, so the installed base of the affected branches plausibly exceeds one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.