Description
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A null pointer dereference flaw exists in the CMS protocol dissector of Wireshark. The bug can cause the application to crash, resulting in a denial‑of‑service condition for users who rely on Wireshark to analyze network traffic. This weakness corresponds to CWE‑476 and is triggered when Wireshark processes data matching the CMS protocol.

Affected Systems

The vulnerability affects Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18, released by the Wireshark Foundation. Any system running these affected builds and parsing CMS traffic is vulnerable.

Risk and Exploitability

The CVSS score is 4.7, indicating moderate severity, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local user execution; a malicious user or software that feeds crafted CMS traffic into Wireshark can trigger the crash, interrupting network monitoring services. Because the flaw leads only to an application crash rather than code execution, the risk is limited to service disruption.

Generated by OpenCVE AI on August 20, 2026 at 09:46 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later.
  • If upgrading immediately is not possible, disable the CMS protocol dissector to prevent the crash from occurring.
  • Restrict use of Wireshark to trusted, privileged users and monitor for crash events to detect attempts to exploit the vulnerability.

Generated by OpenCVE AI on August 20, 2026 at 09:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6471-1 wireshark security update
History

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
Vendors & Products Wireshark
Wireshark wireshark

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark Foundation
Wireshark Foundation wireshark
Vendors & Products Wireshark Foundation
Wireshark Foundation wireshark

Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title NULL Pointer Dereference in Wireshark
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
Wireshark Foundation Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T15:00:57.084Z

Reserved: 2026-08-19T22:34:09.937Z

Link: CVE-2026-76881

cve-icon Vulnrichment

Updated: 2026-08-20T15:00:49.833Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T23:16:18.947

Modified: 2026-09-01T15:19:40.343

Link: CVE-2026-76881

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-19T22:34:59Z

Links: CVE-2026-76881 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses