Description
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Published: 2026-08-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to supply a malicious pcapng file that triggers an out‑of‑bounds read in Wireshark’s file parser, causing the application to crash. The crash results in a denial of service that can disrupt network analysis activities. The weakness is a classic out‑of‑bounds read identified as CWE‑125.

Affected Systems

The flaw exists in Wireshark Foundation Wireshark for versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.

Risk and Exploitability

The CVSS score of 4.7 indicates modest severity, and there is no current EPSS score available. The vulnerability is not in CISA’s KEV catalog. The primary attack vector is inferred to be the use of a crafted pcapng file either locally opened by a user or remotely supplied to a Wireshark instance that parses untrusted files. No documented exploit exists, but any user capable of providing a malformed file could trigger the service disruption.

Generated by OpenCVE AI on August 20, 2026 at 07:51 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.8 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.8 or later
  • Close any potentially malicious pcapng files before opening them with Wireshark
  • If an immediate upgrade is not feasible, configure Wireshark or your environment to prevent automatic opening of untrusted network capture files

Generated by OpenCVE AI on August 20, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 19 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Title Out-of-bounds Read in Wireshark
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-20T16:27:30.288Z

Reserved: 2026-08-19T23:00:01.547Z

Link: CVE-2026-76929

cve-icon Vulnrichment

Updated: 2026-08-20T16:20:46.477Z

cve-icon NVD

Status : Received

Published: 2026-08-19T23:16:21.693

Modified: 2026-08-20T17:19:48.373

Link: CVE-2026-76929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses