CVE-2026-95386: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published Sep 29, 2026
·Updated
TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of Wireshark versions 4.6.0 through 4.6.8 are affected when Wireshark processes a TTL file. The impact is denial of service through an infinite loop.
2
What does an attacker need to exploit it?
The attacker needs to cause a user to process a malicious TTL file in Wireshark. The CVSS vector indicates local attack access and user interaction are required, with no privileges required.