Description
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer over-read condition was discovered in the Tektronix K12xx file parser of Wireshark, which can cause the application to crash and lead to a denial of service. The flaw allows an attacker to trigger the crash by presenting a specially crafted K12xx file, resulting in loss of service availability – an impact described by CWE‑126.

Affected Systems

The vulnerability affects Wireshark products distributed by the Wireshark Foundation. The affected releases are Wireshark 4.6.0 through 4.6.7 and Wireshark 4.4.0 through 4.4.18.

Risk and Exploitability

The CVSS base score of 3.1 indicates a low severity impact. No EPSS score is available and the CVE is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply a malicious Tektronix K12xx file to a user running Wireshark, either locally or via a remote service that processes user files. Because the flaw manifests only when Wireshark parses the file, the attack surface is limited to environments where the application processes untrusted input.

Generated by OpenCVE AI on August 20, 2026 at 07:52 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or newer to apply the buffer over‑read fix.
  • Restart the application after upgrading to ensure the new parser code is loaded.
  • Avoid opening unknown Tektronix K12xx files from untrusted sources until the patch is applied.

Generated by OpenCVE AI on August 20, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Buffer Over-read in Wireshark
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T15:26:28.854Z

Reserved: 2026-08-19T22:34:29.945Z

Link: CVE-2026-76885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:19.430

Modified: 2026-08-20T16:18:22.627

Link: CVE-2026-76885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses