CVE-2026-96415: Stack-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or elevated privileges?
No. The vulnerability is rated with no privileges required, but it requires local attack access and user interaction.
2
What is the expected impact if exploitation succeeds?
The reported impact is high on availability, resulting in a denial of service. No confidentiality or integrity impact is indicated.