CVE-2026-95390: NULL Pointer Dereference in Wireshark
Published Sep 29, 2026
·Updated
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users running Wireshark versions 4.6.0 through 4.6.8 are exposed when they process PEAK CAN TRC files.
2
What does an attacker need to do to trigger the vulnerability?
An attacker needs to persuade a user to open or otherwise process a crafted PEAK CAN TRC file in Wireshark. The attack requires user interaction but no prior privileges.
3
What is the impact of successful exploitation?
Successful exploitation can crash Wireshark, causing a denial of service. The provided severity vector indicates no confidentiality or integrity impact.