Junglewise Threat Intelligence

CVE-2026-15168: Wireshark information disclosure in BLF file parser

CVE-2026-15168 · Severity: low · CVSS 2.5 · Published 2026-07-08

Vendors: Wireshark Foundation.

Executive brief

Wireshark is a widely used network protocol analyzer for troubleshooting and data analysis. A vulnerability in its BLF file reader could allow a specially crafted capture file to trick the software into displaying or exporting sensitive data from the computer's memory. This could lead to the exposure of private information, such as fragments of other network packets or encryption keys, if a user is convinced to open a malicious file.

Technical details

A vulnerability exists in the BLF (Binary Logging Format) file parser's zlib LogContainer reader due to a lack of decompressed-size validation. The parser allocates a buffer based on an attacker-controlled 'uncompressed_size' field using a non-zeroing allocator (g_try_malloc). If a crafted zlib stream decompresses to fewer bytes than declared, the tail of the buffer remains uninitialized. Subsequent object readers then copy these uninitialized heap bytes into decoded packet data, which can be viewed in the UI or exported. This allows for the disclosure of sensitive remnants of previous heap allocations. The issue is fixed in versions 4.6.7 and 4.4.17.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.6, 4.4.0 to 4.4.16

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References