CVE-2026-6870: Access of Uninitialized Pointer in Wireshark
Published Apr 30, 2026
·Updated
GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected Software
3 affected components
Wireshark Wireshark>=4.6.0<=4.6.4, >=4.4.0<=4.4.14
Wireshark Wireshark>=4.4.0<=4.4.14
Wireshark Wireshark>=4.6.0<=4.6.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.5
Event History
Apr 30, 2026
CVE Published
via MITRE·05:33 AM
Data Sourced
via MITRE·05:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Jan 10, 58304
Event
via FIRST·06:15 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-6870?
The severity of CVE-2026-6870 is medium with a score of 5.5.
2
What are the affected versions in CVE-2026-6870?
CVE-2026-6870 affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14.
3
How can I fix CVE-2026-6870?
To fix CVE-2026-6870, upgrade Wireshark to version 4.6.5 or above.
4
What type of vulnerability is CVE-2026-6870?
CVE-2026-6870 is an access of uninitialized pointer vulnerability that can cause a denial of service.
5
What impact does CVE-2026-6870 have on Wireshark?
CVE-2026-6870 can lead to a crash of the GSM RP protocol dissector in Wireshark.