Junglewise Threat Intelligence

CVE-2026-76881: Wireshark CMS protocol dissector null pointer dereference

CVE-2026-76881 · Severity: medium · CVSS 4.7 · Published 2026-08-19

Vendors: Wireshark Foundation.

Executive brief

Wireshark is a network analysis tool used to inspect and debug network traffic. A malformed packet or capture file with a malicious CMS (Cryptographic Message Syntax) structure can cause Wireshark to crash due to a null pointer dereference, resulting in denial of service. An attacker can trigger the crash by sending a crafted packet over the network or distributing a malicious packet capture file.

Technical details

The vulnerability is a null pointer dereference (CWE-476) in the CMS protocol dissector. The cms_verify_msg_digest() function attempts to dereference a pointer (alg) via strcmp() without first checking that the pointer is non-null. When processing a malformed SignedData structure with an empty digest AlgorithmIdentifier, the algorithm identifier string is never initialized, but the verification function is still invoked when eContent is present. The attack requires no valid signature, certificate, or digest—only a crafted CMS message with specific structural properties. An attacker can trigger the crash by injecting a malformed packet onto the network or distributing a malicious PCAP file. Patched versions 4.6.8 and 4.4.18 add null checks before the strcmp() call.

Affected products

  • Wireshark Foundation Wireshark 4.4.0 to 4.4.17, 4.6.0 to 4.6.7

Timeline

  • 2026-08-12: disclosed: Wireshark security advisory wnpa-sec-2026-76 published
  • 2026-08-19: patched: Fixed versions 4.6.8 and 4.4.18 released

References