CVE-2026-6868: Stack-based Buffer Overflow in Wireshark
HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.5 - Compensating control
If immediate upgrade is not possible, mitigate the denial-of-service risk by limiting exposure to untrusted network traffic until Wireshark can be upgraded to 4.6.5 or above.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6868?
CVE-2026-6868 has a severity rating that indicates it allows for a denial of service due to a stack-based buffer overflow.
How do I fix CVE-2026-6868?
To fix CVE-2026-6868, upgrade to Wireshark version 4.6.5 or higher for the 4.6.x series or 4.4.15 or higher for the 4.4.x series.
What versions of Wireshark are affected by CVE-2026-6868?
CVE-2026-6868 affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14.
What are the risks associated with CVE-2026-6868?
The primary risk associated with CVE-2026-6868 is a denial of service attack that can crash the application.
Can CVE-2026-6868 be exploited remotely?
Yes, CVE-2026-6868 can potentially be exploited remotely if malicious HTTP packets are processed by the vulnerable version of Wireshark.