Executive brief
Wireshark, a widely used network protocol analyzer, is vulnerable to a crash when processing specifically crafted capture files. If a user opens a malicious pcapng file and attempts to save, export, or rewrite it using tools like editcap or tshark, the application may crash or experience memory corruption. This could disrupt network analysis workflows or automated traffic processing systems.
Technical details
A heap-based buffer overflow (CWE-122) exists in the pcapng Darwin Process Info Block (DPIB) rewrite path in Wireshark versions 4.6.0 through 4.6.6. The vulnerability is caused by a length discrepancy between 'compute_dpib_option_size()', which assumes a fixed 16-byte size for 'OPT_DPIB_UUID', and 'put_dpib_option()', which copies the actual stored byte length from the input file. An attacker can trigger this by providing a pcapng file containing a DPIB UUID option longer than 16 bytes. Exploitation requires the victim to rewrite or export the malicious file using Wireshark, editcap, or tshark ('-w' flag), resulting in an out-of-bounds write and subsequent application crash (Denial of Service).
Affected products
- Wireshark Foundation Wireshark 4.6.0 to 4.6.6
Timeline
- 2026-05-29: other: Vulnerability discovered and verified by researcher
- 2026-07-08: disclosed: CVE published and advisory released