CVE-2026-76883: Heap-based Buffer Overflow in Wireshark
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Catapult DCT2000 file parserto a version that resolves this vulnerability.Fixed in 4.6.8 - Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Patch Heap-based Buffer Overflow
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Wireshark versions 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are exposed when processing Catapult DCT2000 files.
What does exploitation require?
Exploitation requires local access, high attack complexity, and user interaction. The issue can cause a denial of service through a crash; no confidentiality or integrity impact is listed.
Are unaffected Wireshark versions identified?
The provided information identifies affected version ranges only: 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. It does not state the fixed versions.