🚨 CVE-2026-76880
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Fix potential heap corruption in UMTS RRC (#21478) · Issues · Wireshark Foundation / Wireshark · GitLab
A protocol-valid, packet-controlled RB-Identity value in the UMTS RRC dissector is stored in RRC private state and later used directly as an index into rrc_ciphering_info.seq_no, whose...
🚨 CVE-2026-76881
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
CMS MessageDigest verification dereferences missing algorithm (#21446) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Research: [Security] CMS MessageDigest verification dereferences missing algorithm
🚨 CVE-2026-76882
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Heap OOB read in packet-btatt.c:11504 (#21424) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary Heap out-of-bounds read in the Bluetooth ATT dissector when handling Read Multiple Variable Response (opcode 0x21). The...
🚨 CVE-2026-76883
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Heap OOB write in wiretap/catapult_dct2000.c:1382 - off-by-one in DCT2000 file reader (#21427) · Issues · Wireshark Foundation…
Summary Heap out-of-bounds write in the Catapult DCT2000 wiretap file reader at catapult_dct2000.c:1382. floor(data_chars/2) bytes are allocated but...
🚨 CVE-2026-76884
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Short ERF provenance gen_time tag causes an eight-byte heap out-of-bounds read (#21415) · Issues · Wireshark Foundation / Wireshark…
Summary The ERF metadata parser copies an eight-byte gen_time value without checking that the tag contains eight value...
🚨 CVE-2026-76885
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Tektronix K12 .rf5 blob handling causes a heap out-of-bounds read (#21414) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary The Tektronix K12 .rf5 reader can pass a length larger than its record buffer to process_packet_data().
🚨 CVE-2026-76886
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
EAX CMAC 16-bit length truncation can overflow heap on large C12.22 cleartext-auth payloads (#21439) · Issues · Wireshark Foundation…
From AISLE Security: [Security] EAX CMAC 16-bit length truncation can overflow heap on large C12.22 cleartext-auth payloads
🚨 CVE-2026-76887
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Wireshark reassembly memory-safety report (#21423) · Issues · Wireshark Foundation / Wireshark · GitLab
Daniel Birtwhistle reported the following: Case: WS-REASM-WRAP-01 Audience: Wireshark security team Hello Wireshark Security Team, My name is Daniel Birtwhistle....
🚨 CVE-2026-76888
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
RDP8/ZGFX decompressor: off-by-one heap overflow in zgfx_write_literal() (outputSegment[65536]) (ANT-2026-05VXN1Y6) (#21396) ·…
I am writing to report a stack-buffer-overflow (write) that is triggerable by way of the Wireshark fuzzing harness fuzzshark) This is a security issue that...
🚨 CVE-2026-76889
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
UMTS FP MAC-is descriptor count causes fixed-array out-of-bounds writes (#21413) · Issues · Wireshark Foundation / Wireshark ·…
Summary The UMTS FP dissector does not limit the number of MAC-is SDU descriptors before using the count...
🚨 CVE-2026-76890
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-array iograph tap listeners on error path (ANT-2026-GACTPNVK) (#21399) · Issues · Wireshark…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...
🚨 CVE-2026-76891
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-object rtp-streams tap listener on error path (ANT-2026-27KVBTTP) (#21395) · Issues…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...
🚨 CVE-2026-76917
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
AVRCP Vendor-Dependent Fragment Reassembly — uint32_t Integer Overflow → Heap Buffer Overflow (#21488) · Issues · Wireshark Foundation…
AVRCP Vendor-Dependent Fragment Reassembly — uint32_t Integer Overflow → Heap Buffer Overflow 1. Executive Summary
🚨 CVE-2026-76918
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
SSH dissector: heap buffer overflow in curve25519 key exchange (#21465) · Issues · Wireshark Foundation / Wireshark · GitLab
Affected: master, release-4.6, release-4.4. Introduced in 3.4.0 (2020-10-29) with SSH decryption support; unfixed on every branch as of 2026-08-02. Impact: heap out-of-bounds write of...
🚨 CVE-2026-76919
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Malformed ESS BIT STRING can use uninitialized TVB pointer in attribute-flag dissection (#21467) · Issues · Wireshark Foundation…
From AISLE Security: Summary A malformed BER BIT STRING in an ESS security-category attribute can make...
🚨 CVE-2026-76920
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
3GPP log decoder can write one byte past packet buffer (#21454) · Issues · Wireshark Foundation / Wireshark · GitLab
From Aisle Security: [Security] 3GPP log decoder writes one byte past packet buffer
🚨 CVE-2026-76921
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
CMS RC2 parameter decoding reuses freed capability-tree pointer (#21457) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] CMS RC2 parameter decoding reuses freed capability-tree pointer
🚨 CVE-2026-76922
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
BR/EDR fragmented L2CAP uses an unregistered reassembly table (#21452) · Issues · Wireshark Foundation / Wireshark · GitLab
Aisle Security reported: [Security] BR/EDR fragmented L2CAP uses an unregistered reassembly table
🚨 CVE-2026-76923
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Short +XAPL accessory parameter causes heap out-of-bounds read (#21451) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Short +XAPL accessory parameter causes heap out-of-bounds read
🚨 CVE-2026-76924
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Kerberos learned-key formatting reads past short EncryptionKey (#21449) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Kerberos learned-key formatting reads past short EncryptionKey
🚨 CVE-2026-76927
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
H.245 returnedFunction nested GenericMessage dereferences NULL packet state (#21447) · Issues · Wireshark Foundation / Wireshark…
From AISLE Security: [Security] H.245 returnedFunction nested GenericMessage dereferences NULL packet state