CVE-2026-76918: Heap-based Buffer Overflow in Wireshark
Published Aug 19, 2026
·Updated
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<4.6.7, >=4.4.0<4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark versions are affected?
Affected versions are Wireshark 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What does an attacker need to do to trigger the issue?
The issue is in the SSH protocol dissector and requires user interaction. The provided vector indicates local attack access and no privileges are required.
3
What is the expected impact?
Successful exploitation can crash Wireshark, resulting in a denial of service. The supplied severity vector indicates no confidentiality or integrity impact.