CVE-2026-95392: Buffer Over-read in Wireshark
Published Sep 29, 2026
·Updated
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:32 AM
Data Sourced
via MITRE·09:32 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark versions are affected?
Wireshark versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18 are affected.
2
What access does an attacker need to trigger the denial of service?
The vector is local and requires user interaction. The provided data does not specify the exact malicious input or interaction required.
3
What is the impact if exploitation succeeds?
Successful exploitation can crash Wireshark, causing a denial of service. No confidentiality or integrity impact is indicated by the supplied CVSS vector.