Description
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A NULL pointer dereference occurs while parsing the H.245 protocol in Wireshark 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18, causing the application to crash. The vulnerability leads to a denial of service for users running the affected versions and is identified as CWE‑476.

Affected Systems

The Wireshark Foundation’s Wireshark product is affected. Users running any of the following versions are vulnerable: 4.6.0–4.6.7 and 4.4.0–4.4.18. Versions 4.6.8 and later, as well as the latest 4.4 series past 4.4.18, contain the fix.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires an attacker to supply crafted H.245 packets—either through a malicious capture file or by manipulating traffic seen by Wireshark—so it is a local or captured‑traffic‑based vector rather than a remote network attack. Users who routinely analyze H.245 traffic or load untrusted packet captures are at higher risk.

Generated by OpenCVE AI on August 20, 2026 at 07:51 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later
  • If an upgrade is temporarily infeasible, avoid opening or importing unknown H.245 capture files until a patch is available
  • Disable the H.245 dissector in Wireshark’s preferences when it is not needed for analysis

Generated by OpenCVE AI on August 20, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title NULL Pointer Dereference in Wireshark
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-19T23:00:11.516Z

Reserved: 2026-08-19T22:59:51.521Z

Link: CVE-2026-76927

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:21.447

Modified: 2026-08-19T23:16:21.447

Link: CVE-2026-76927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses