ZeroHour

CVE-2026-76929

PoC mass

Out-of-bounds read in Wireshark pcapng parser causes denial of service

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-76929 is an out-of-bounds read (CWE-125) in the pcapng capture-file parser of Wireshark, affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when the application parses a malformed, attacker-crafted pcapng file, causing the parser to read beyond the intended buffer and crash the process. The impact is denial of service only: the capture session or application terminates, with no code execution and no confidentiality or integrity impact (CVSS 5.5, local vector requiring user interaction). Anyone running the affected 4.4.x or 4.6.x releases who opens capture files from untrusted sources is affected; remote attackers cannot exploit it directly without getting a user to process the file. There is no evidence of in-the-wild exploitation so far: the flaw is not in CISA KEV, EPSS is 0.1%, and the only public reference is a Wireshark bug-tracker issue (work item 21460).

What to do: Upgrade Wireshark to a release later than 4.6.7 in the 4.6 branch or later than 4.4.18 in the 4.4 branch (the next maintenance release in each branch). Until patched, avoid opening pcapng capture files from untrusted sources with affected versions, and verify the installed Wireshark version before processing third-party capture files.

Affected
wireshark4.6.0 to 4.6.7
wireshark4.4.0 to 4.4.18
Estimated exposure
mass≈millions of users/installations (de facto standard free packet analyzer) — Wireshark is freely distributed and widely regarded as the most-deployed network packet analyzer, with installations on a large share of analyst and administrator desktops, so installs running the affected 4.4.x/4.6.x branches plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.