CVE-2026-96420: Buffer Over-read in Wireshark
Published Sep 29, 2026
·Updated
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wiresharkto a version that resolves this vulnerability.Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this denial-of-service issue?
Users running Wireshark versions 4.6.0 through 4.6.8 or 4.4.0 through 4.4.18 are affected when processing Toshiba files.
2
What must an attacker do to trigger the issue?
The attacker must cause Wireshark to process a crafted Toshiba file. The CVSS vector indicates local attack access, high attack complexity, no required privileges, and user interaction.