CVE-2026-96416: Heap-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users running Wireshark versions 4.6.0 through 4.6.8 or 4.4.0 through 4.4.18 are affected when Wireshark processes IEEE 802.11 traffic.
2
What does an attacker need to do to trigger the vulnerability?
The attacker needs to cause a user to process crafted IEEE 802.11 protocol data in Wireshark. The CVSS vector indicates local attack access and user interaction are required, while no privileges are required.
3
What is the impact of successful exploitation?
Successful exploitation can crash Wireshark, resulting in denial of service. The provided impact information does not indicate confidentiality or integrity impact.