Description
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The RRC protocol dissector in Wireshark has an out-of-bounds write that can crash the application, providing an out-of-bounds overwrite weakness (CWE-787). When exploited, the crash results in denial of service for users running the affected versions of the software.

Affected Systems

Wireshark Foundation’s Wireshark product versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are vulnerable. Users must upgrade to version 4.6.8 or later to address the flaw.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered by feeding crafted RRC protocol packets to a running Wireshark instance, causing an out-of-bounds write that terminates the process. The attack vector is likely remote, as Wireshark can process network traffic captured from external sources.

Generated by OpenCVE AI on August 20, 2026 at 08:15 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading Wireshark to version 4.6.8 or later.
  • If immediate upgrading is not possible, disable or skip the RRC protocol dissector in Wireshark’s preferences to prevent processing of malicious RRC packets.
  • Monitor Wireshark logs for unexpected crashes and ensure that only trusted traffic is fed into the application, using network segmentation or filtering controls as a temporary protective measure.

Generated by OpenCVE AI on August 20, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Out-of-bounds Write in Wireshark
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T15:26:30.315Z

Reserved: 2026-08-19T22:34:04.934Z

Link: CVE-2026-76880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:18.830

Modified: 2026-08-20T16:18:22.187

Link: CVE-2026-76880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:30:04Z

Weaknesses