CVE-2026-76881: NULL Pointer Dereference in Wireshark
Published Aug 19, 2026
·Updated
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:34 PM
Data Sourced
via MITRE·10:34 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark releases are affected?
The affected release ranges are 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What access and conditions are required to trigger the crash?
The CVSS vector indicates local attack access, high attack complexity, no privileges required, and user interaction required. The impact is denial of service through a crash in the CMS protocol dissector.