Description
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Published: 2026-08-13
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack‑based buffer overflow in the Gammu DCT3 trace file parser of Wireshark. When a malformed trace file is parsed, the overflow causes the application to crash, resulting in a denial of service. The flaw is identified as CWE‑121 and leads to loss of availability for users relying on Wireshark for packet analysis.

Affected Systems

Affected versions are Wireshark 4.6.0 through 4.6.7. The product is Wireshark from Wireshark Foundation. Upgrading to version 4.6.8 or later eliminates the flaw.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity. Because the exploit requires the ability to supply a crafted Gammu DCT3 trace file, the attack vector is local and file‑based; remote exploitation was not documented. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Nevertheless, any environment that processes untrusted trace files should address the flaw promptly.

Generated by OpenCVE AI on August 13, 2026 at 09:28 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later
  • Prevent loading untrusted Gammu DCT3 trace files until the vulnerability is fixed
  • Run Wireshark with the least privileges or in an isolated environment to contain a crash
  • Monitor the Wireshark update channel for future security patches

Generated by OpenCVE AI on August 13, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Thu, 13 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Title Stack-based Buffer Overflow in Wireshark
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-13T08:04:34.168Z

Reserved: 2026-08-13T07:35:04.042Z

Link: CVE-2026-19695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T09:17:12.857

Modified: 2026-08-13T09:17:12.857

Link: CVE-2026-19695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow