CVE-2026-76886: Heap-based Buffer Overflow in Wireshark
Published Aug 19, 2026
·Updated
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wiresharkto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark versions are affected?
The affected version ranges are Wireshark 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What is required to trigger the issue?
The vulnerability is in the C12.22 protocol dissector and is reachable over the network without authentication or user interaction. Exploitation has high attack complexity.
3
What is the documented impact?
The documented impact is denial of service caused by a heap-based buffer overflow in the C12.22 protocol dissector.