ZeroHour

CVE-2026-76928

PoC mass

Remote DoS via NULL pointer dereference in Wireshark X.509IF dissector

CVSS 3.1
7.5 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-76928 is a NULL pointer dereference (CWE-476) in the X.509IF protocol dissector of Wireshark that causes the application to crash while parsing malformed protocol data. An attacker can trigger it by sending crafted packets onto a network that an affected Wireshark or tshark instance is capturing, or by getting a crafted capture file dissected, with no authentication or user interaction required (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). The impact is denial of service of the analysis tool itself (high availability impact, no confidentiality or integrity loss); the monitored network is unaffected. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected. Exploitation status: not in CISA KEV, EPSS is low at 0.3% (20th percentile), and one public reference exists (the upstream GitLab issue), but no in-the-wild exploitation is known.

What to do: Upgrade to a Wireshark release later than 4.6.7 (4.6 branch) or later than 4.4.18 (4.4 branch). Until patched, avoid live-capturing untrusted network traffic with affected versions, or disable the X.509IF dissector via Analyze → Enabled Protocols. Inventory hosts running Wireshark/tshark 4.6.0–4.6.7 or 4.4.0–4.4.18, prioritizing analyst workstations and monitoring systems exposed to attacker-reachable traffic.

Affected
wireshark4.6.0 through 4.6.7
wireshark4.4.0 through 4.4.18
Estimated exposure
mass≈ millions of installed users worldwide (Wireshark's global install base) — Wireshark is the de facto standard open-source packet analyzer with cumulative downloads in the tens of millions and broad bundling in security and networking toolchains, so the installed base plausibly reaches millions, though only hosts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.