CVE-2026-76919: Use of Uninitialized Variable in Wireshark
Published Aug 19, 2026
·Updated
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wireshark ESS protocol dissectorto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark versions are affected?
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are affected.
2
What is the practical impact of successful exploitation?
Successful exploitation can crash Wireshark, resulting in a denial of service. The provided information does not indicate confidentiality or integrity impact.
3
Does exploiting this issue require authentication or user interaction?
The supplied severity vector indicates network attack access, low attack complexity, no privileges required, and no user interaction required.