CVE-2026-76929: Out-of-bounds Read in Wireshark
Published Aug 19, 2026
·Updated
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users running Wireshark versions 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected when processing a crafted Pcapng file.
2
What does exploitation require?
An attacker needs to cause a user to process a malicious Pcapng file in Wireshark. The attack is local, has high attack complexity, and requires user interaction; it does not require privileges.
3
What is the impact if exploitation succeeds?
Successful exploitation can crash the Pcapng file parser, resulting in a denial of service. The provided assessment indicates no confidentiality or integrity impact.