CVE-2026-95388: Heap-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The affected component is the Sharkd utility in Wireshark versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.
2
What is the practical impact of successful exploitation?
Successful exploitation can crash the Sharkd utility, resulting in denial of service. The provided data does not indicate confidentiality or integrity impact.
3
What level of attacker access is required?
The vector is local and requires user interaction. No privileges are required according to the supplied severity vector.