CVE-2026-95387: Heap-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark releases are affected?
The affected release ranges are Wireshark 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.
2
What can exploitation cause?
A heap-based buffer overflow in the SPDY protocol dissector allows denial of service.
3
Does exploitation require credentials or user interaction?
The supplied vector indicates that exploitation is network-reachable and requires neither privileges nor user interaction. It also indicates high attack complexity.