Description
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reachable assertion flaw in Wireshark’s BUSMASTER file parser causes an abnormal exit when processing certain file types, resulting in a denial of service that terminates the application and delays packet capture operations. The issue falls under CWE-617, indicating improper control flow handling.

Affected Systems

Wireshark Foundation Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are vulnerable.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score is not available so exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. Based on the description, an attacker who can supply or trick Wireshark into opening a crafted BUSMASTER file can trigger the assertion, causing the application to crash, suggesting a local or remote file input attack vector.

Generated by OpenCVE AI on August 20, 2026 at 07:52 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later, which contains the fixed assertion in the BUSMASTER file parser.
  • If you must remain on an older release, restrict file import to trusted users and directories or run Wireshark in a sandboxed environment to limit the impact of a malicious file.
  • Continuously monitor Wireshark release notes for new security updates and patch the software promptly when available.

Generated by OpenCVE AI on August 20, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Reachable Assertion in Wireshark
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T15:26:28.415Z

Reserved: 2026-08-19T22:59:46.651Z

Link: CVE-2026-76926

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:21.320

Modified: 2026-08-20T16:18:29.360

Link: CVE-2026-76926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses