Description
DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow that occurs in Wireshark’s DBS Etherwatch file parser. It causes the application to crash when parsing a malformed DBS Etherwatch file, resulting in a denial of service. The flaw is classified as CWE‑121 and is a classic stack corruption weakness. Attackers who can supply a malicious file or otherwise trigger the parser may exploit the overflow, though the crash does not provide remote code execution.

Affected Systems

Affected are Wireshark 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The product is Wireshark from the Wireshark Foundation.

Risk and Exploitability

The CVSS score of 7.5 indicates high impact, while the EPSS score of <1% shows a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. It vector is remote, involving the delivery of a crafted DBS Etherwatch file to a system running Wiresh by a user or system component that processes untrusted files, the denial of service can interrupt network monitoring and analysis functions.

Generated by OpenCVE AI on July 29, 2026 at 13:20 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.7 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.7 or later to apply the buffer‑overflow fix.
  • Run Wireshark with the least privileges or in a sandboxed environment to isolate the impact of a crash.
  • Configure system monitoring to detect unexpected Wireshark termination and implement automated fail‑ service disruption.

Generated by OpenCVE AI on July 29, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Title Stack-based Buffer Overflow in Wireshark
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T13:45:58.260Z

Reserved: 2026-07-08T20:45:33.866Z

Link: CVE-2026-15167

cve-icon Vulnrichment

Updated: 2026-07-09T13:45:55.164Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T20:51:00Z

Links: CVE-2026-15167 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:30:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-1286

    Improper Validation of Syntactic Correctness of Input