CVE-2026-76880: Out-of-bounds Write in Wireshark
Published Aug 19, 2026
·Updated
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>4.6.0<=4.6.7, >4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:44 PM
Data Sourced
via MITRE·10:44 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark versions are affected?
Affected versions are Wireshark 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What does an attacker need to do to trigger the issue?
The issue is network-reachable, requires no privileges or user interaction, and can be triggered through the RRC protocol dissector. Successful exploitation can cause a denial of service by crashing Wireshark.
3
Is there evidence that confidentiality or data integrity is affected?
No. The supplied impact vector lists confidentiality and integrity impact as none; the stated impact is availability loss.