Description
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer over-read bug in the ERF file parser of Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 causes the application to crash when parsing malformed ERF files, resulting in a denial of service. The flaw triggers when input data extends beyond the allocated buffer boundaries, which leads to an ungainly termination of the program without any exploit code execution or data exfiltration.

Affected Systems

The vulnerability affects Wireshark Foundation’s Wireshark product, specifically releases 4.6.0‑4.6.7 and 4.4.0‑4.4.18. Users running any of these versions and opening ERF files from untrusted or potentially corrupted sources are at risk.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity; the EPSS score of < 1% suggests a very low probability of exploitation, and the lack of a KEV listing further reduces the urgency. Based on the description, the attack vector is limited to locally opening a crafted ERF file, which implies that only users or processes with access to such files can trigger the denial of service. Consequently, the risk is considered low but mitigable through updating the software.

Generated by OpenCVE AI on August 21, 2026 at 04:53 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or higher
  • If an upgrade is not feasible, avoid opening ERF files from untrusted sources or them from the system
  • Run Wireshark under the lowest required privileges to limit the impact of potential crashes

Generated by OpenCVE AI on August 21, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6471-1 wireshark security update
History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-130
References
Metrics threat_severity

None

threat_severity

Low


Thu, 20 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Buffer Over-read in Wireshark
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T14:27:14.147Z

Reserved: 2026-08-19T22:34:24.939Z

Link: CVE-2026-76884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T23:16:19.313

Modified: 2026-08-31T19:15:17.613

Link: CVE-2026-76884

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-19T22:35:14Z

Links: CVE-2026-76884 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T05:00:13Z

Weaknesses
  • CWE-126

    Buffer Over-read

  • CWE-130

    Improper Handling of Length Parameter Inconsistency