CVE-2026-76921: Use After Free in Wireshark
Published Aug 19, 2026
·Updated
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require privileges or user interaction?
The vector indicates no privileges are required, but user interaction is required. The attack vector is local.
2
What is the expected security impact?
The reported impact is denial of service through a crash. Confidentiality and integrity impacts are listed as none, while availability impact is high.
3
How can I determine whether an installation is affected?
Check the Wireshark version. The affected ranges are 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.