CVE-2026-76928
PoC massRemote DoS via NULL pointer dereference in Wireshark X.509IF dissector
CVE-2026-76928 is a NULL pointer dereference (CWE-476) in the X.509IF protocol dissector of Wireshark that causes the application to crash while parsing malformed protocol data. An attacker can trigger it by sending crafted packets onto a network that an affected Wireshark or tshark instance is capturing, or by getting a crafted capture file dissected, with no authentication or user interaction required (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). The impact is denial of service of the analysis tool itself (high availability impact, no confidentiality or integrity loss); the monitored network is unaffected. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected. Exploitation status: not in CISA KEV, EPSS is low at 0.3% (20th percentile), and one public reference exists (the upstream GitLab issue), but no in-the-wild exploitation is known.
What to do: Upgrade to a Wireshark release later than 4.6.7 (4.6 branch) or later than 4.4.18 (4.4 branch). Until patched, avoid live-capturing untrusted network traffic with affected versions, or disable the X.509IF dissector via Analyze → Enabled Protocols. Inventory hosts running Wireshark/tshark 4.6.0–4.6.7 or 4.4.0–4.4.18, prioritizing analyst workstations and monitoring systems exposed to attacker-reachable traffic.
| wireshark | 4.6.0 through 4.6.7 |
| wireshark | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.