Description
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference occurs in the X.509IF protocol dissector of Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. The defect allows an attacker to crash the application by sending a specially crafted packet, leading to a denial of service. The weakness is a classic null reference error (CWE‑476) and an improper initialization flaw (CWE‑825).

Affected Systems

The vulnerability affects Wireshark released by Wireshark Foundation. Versions 4.4.0 to 4.4.18 and 4.6.0 to 4.6.7 are vulnerable; any installation of these versions must be considered exposed until updated.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is 0.284% (0.00284), indicating a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog, implying that no widespread public exploits have yet been documented. The likely attack vector is through a crafted X.509IF packet delivered over a network that the Wireshark instance is capturing. Successful exploitation would crash Wireshark, causing loss of packet capture capability and potentially interrupting monitoring services.

Generated by OpenCVE AI on August 21, 2026 at 04:06 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or newer
  • Disable the X.509IF dissector or turn off automatic protocol processing if an upgrade cannot be applied immediately
  • Apply the update to all systems running Wireshark, including monitor servers, to ensure the crash condition no longer exists

Generated by OpenCVE AI on August 21, 2026 at 04:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title NULL Pointer Dereference in Wireshark
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T16:27:30.441Z

Reserved: 2026-08-19T22:59:56.519Z

Link: CVE-2026-76928

cve-icon Vulnrichment

Updated: 2026-08-20T16:20:51.591Z

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:21.570

Modified: 2026-08-20T17:19:48.260

Link: CVE-2026-76928

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-19T23:00:16Z

Links: CVE-2026-76928 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:15:04Z

Weaknesses
  • CWE-476

    NULL Pointer Dereference

  • CWE-825

    Expired Pointer Dereference