CVE-2026-76924: Out-of-bounds Read in Wireshark
Published Aug 19, 2026
·Updated
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>4.6.0<=4.6.7, >4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are affected. Installations outside those stated ranges are not identified in the provided data.
2
What does an attacker need to exploit this issue?
The supplied CVSS vector indicates local attack access, no required privileges, and user interaction. The provided data does not describe a remote exploitation path.
3
What is the expected impact of successful exploitation?
Successful exploitation can crash Wireshark, resulting in denial of service. The supplied CVSS vector indicates no confidentiality or integrity impact.