CVE-2026-76920: Out-of-bounds Write in Wireshark
Published Aug 19, 2026
·Updated
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Wireshark installations running versions 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected when they parse a 3GPP phone log file.
2
What does an attacker need to exploit it?
Exploitation requires convincing a user to open or otherwise parse a crafted 3GPP phone log file in Wireshark. The available data indicates a local attack vector and required user interaction.
3
What is the impact of successful exploitation?
Successful exploitation can crash Wireshark, resulting in denial of service. No confidentiality or integrity impact is indicated by the provided CVSS vector.