CVE-2026-76890: Expired Pointer Dereference in Wireshark
Published Aug 19, 2026
·Updated
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark (sharkd)>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:46 PM
Data Sourced
via MITRE·10:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects sharkd in Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What impact can exploitation have?
Successful exploitation can cause a sharkd crash, resulting in denial of service. The provided data does not indicate confidentiality or integrity impact.
3
What attacker interaction is indicated by the severity vector?
The vector indicates network reachability, no required privileges, and required user interaction. It also rates attack complexity as high.