CVE-2026-95393: Heap-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Wireshark versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18 are affected.
2
What does an attacker need to do to trigger the issue?
The CVSS vector indicates local attack vector, high attack complexity, no privileges required, and user interaction required. Exploitation results in a denial of service through a crash in the CSN.1 protocol dissector.
3
What is the impact if exploitation succeeds?
The stated impact is denial of service. The CVSS vector reports no confidentiality or integrity impact and high availability impact.