CVE-2026-3202: NULL Pointer Dereference in Wireshark
Published Feb 25, 2026
·Updated
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Affected Software
2 affected components
Wireshark Wireshark>=4.6.0<=4.6.3
Wireshark Wireshark>=4.6.0<4.6.4
Remediation
Information
Upgrade to version 4.6.4 or above
Event History
Feb 25, 2026
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:20 PM
DescriptionSeverityWeaknessAffected Software
Oct 1, 58139
Event
via FIRST·11:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-3202?
The severity of CVE-2026-3202 is classified as high due to its potential to cause denial of service.
2
How do I fix CVE-2026-3202?
To fix CVE-2026-3202, upgrade Wireshark to version 4.6.4 or later.
3
Which versions of Wireshark are affected by CVE-2026-3202?
CVE-2026-3202 affects Wireshark versions 4.6.0 to 4.6.3.
4
What is the impact of CVE-2026-3202 on systems using Wireshark?
The impact of CVE-2026-3202 is a crash of the application leading to a denial of service.
5
Is there a patch available for CVE-2026-3202?
Yes, a patch is available in Wireshark version 4.6.4 and later, which resolves this vulnerability.