CVE-2026-76889: Heap-based Buffer Overflow in Wireshark
Published Aug 19, 2026
·Updated
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to trigger the crash?
The attack requires local access, high attack complexity, and user interaction. The available data does not specify the exact input or interaction needed.
2
Which installations are affected?
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are affected. The issue is in the UMTS FP protocol dissector and can cause denial of service.