Description
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Wireshark’s SSH protocol dissector contains a heap‑based buffer overflow that causes the application to crash when processing malformed packets. The vulnerability can lead to a denial of service, leaving the user unable to analyze network traffic until Wireshark is restarted. This weakness is captured by CWE‑122 and CWE‑248.

Affected Systems

The flaw exists in Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18, produced by the Wireshark Foundation. The issue is reported for all builds of the Wireshark client that include the SSH dissector and is included in the listed affected versions.

Risk and Exploitability

The CVSS score is 5.5, a moderate rating that indicates a non‑critical but significant impact. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, suggesting no known active exploitation at this time. The likely attack vector is the delivery of crafted SSH packets to a running Wireshark instance; an attacker would need network access to the host where Wireshark is listening or local access to inject hostile packets into the capture stream. The vulnerability is remotely exploitable through traffic that reaches the program, but it remains most practical for attackers who can influence the content of packets analyzed by Wireshark.

Generated by OpenCVE AI on August 22, 2026 at 02:27 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later to apply the vendor’s fix.
  • If an upgrade is not immediately possible, disable the SSH protocol dissector to prevent the crash from occurring on malformed packets.
  • Track application stability after changes and report any crashes to Wireshark maintain for confirmation of the mitigation.

Generated by OpenCVE AI on August 22, 2026 at 02:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6471-1 wireshark security update
History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

Sat, 22 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-248
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Heap-based Buffer Overflow in Wireshark
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T15:26:29.901Z

Reserved: 2026-08-19T22:44:15.542Z

Link: CVE-2026-76918

cve-icon Vulnrichment

Updated: 2026-08-20T15:23:15.195Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T23:16:20.487

Modified: 2026-08-31T19:13:43.953

Link: CVE-2026-76918

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-19T22:45:05Z

Links: CVE-2026-76918 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T02:30:17Z

Weaknesses