Description
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Wireshark’s C12.22 protocol dissector contains a stack-based buffer overflow that can be triggered when parsing certain malformed input, causing the application to crash. The vulnerability is classified as CWE-121 and results in denial of service by terminating the Wireshark session.

Affected Systems

Wireshark Foundation’s Wireshark software is affected in versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. The vendor recommends upgrading to 4.6.8 or later to remove the flaw.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in KEV. While the official description does not specify the attacker’s required environment, it is reasonable to infer that the exploit requires feeding a crafted capture file to the dissector, which suggests a local or user‑initiated attack vector rather than a remote network‑based one.

Generated by OpenCVE AI on August 20, 2026 at 07:55 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later
  • If an upgrade cannot be performed immediately, run Wireshark with the minimum privileges necessary and restrict the ability to load capture files to trusted users only
  • Monitor Wireshark logs and system performance for unexpected crashes and investigate any incidents promptly

Generated by OpenCVE AI on August 20, 2026 at 07:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Stack-based Buffer Overflow in Wireshark
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-19T22:44:00.527Z

Reserved: 2026-08-19T22:34:00.090Z

Link: CVE-2026-76879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:18.700

Modified: 2026-08-19T23:16:18.700

Link: CVE-2026-76879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow