CVE-2026-95389: Heap-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark releases should be treated as affected?
The affected release ranges are 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18. Installations in either range should be considered vulnerable.
2
Does an attacker need credentials or user interaction to attempt exploitation?
The CVSS vector indicates network reachability, no privileges required, and no user interaction required. It also rates attack complexity as high.
3
Is the reported impact limited to a crash?
The vulnerability description specifically identifies denial of service through an SCTP dissector crash. The supplied CVSS vector rates confidentiality, integrity, and availability impacts as high.