Description
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Wireshark’s 3GPP phone log file parser contains an out‑of‑bounds write that corrupts memory when it processes a malformed log file. The resulting buffer overflow causes the application to crash, which results in a denial of service for the running instance. The flaw does not allow attackers to read or exfiltrate data or execute arbitrary code, but it does interrupt service availability. The weakness is a classic buffer overflow, classified as CWE‑787.

Affected Systems

The flaw affects Wireshark Foundation’s Wireshark product, specifically versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. Users running any of these releases should verify their installed version and plan an upgrade.

Risk and Exploitability

The nominal CVSS base score of 4.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower mainstream exploitation risk. The vulnerability can be exercised by feeding a malicious 3GPP phone log file to Wireshark; this is typically a local action but could be leveraged remotely if the software is instructed to parse untrusted files from network sources. While the exact likelihood of exploitation is not documented, the impact is a service interruption for the affected instance.

Generated by OpenCVE AI on August 20, 2026 at 07:53 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later to eliminate the out‑of‑bounds write in the 3GPP phone log parser.
  • If an upgrade is not immediately possible, restrict the use of untrusted 3GPP phone log files by allowing Wireshark to process only files from verified or secured sources; consider implementing file‑level access controls or a sandbox to isolate the parsing operation.
  • Deploy process containment, such as running Wireshark in a sandboxed environment or container, to limit the impact of a crash on the host system and reduce the risk of service disruption in shared or sensitive environments.

Generated by OpenCVE AI on August 20, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6471-1 wireshark security update
History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Out-of-bounds Write in Wireshark
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T15:26:29.604Z

Reserved: 2026-08-19T22:44:25.534Z

Link: CVE-2026-76920

cve-icon Vulnrichment

Updated: 2026-08-20T15:23:04.290Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T23:16:20.727

Modified: 2026-08-31T19:15:54.587

Link: CVE-2026-76920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses