CVE-2026-96423: Heap-based Buffer Overflow in Wireshark
Published Sep 29, 2026
·Updated
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.8, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.9
Event History
Sep 29, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploiting this require elevated privileges or user interaction?
The CVSS vector indicates local access and user interaction are required. It does not require privileges.
2
Can this issue disclose data or modify it?
The CVSS impact indicates no confidentiality or integrity impact. Its assessed impact is on availability, consistent with a crash or denial of service.