Executive brief
Wireshark is a widely-used packet analyzer and protocol sniffer used to inspect network traffic. A flaw in its packet reassembly engine could crash the application when processing malformed captures or live traffic containing certain fragmented packets, causing denial of service to analysts and automation systems relying on Wireshark to process network data.
Technical details
The vulnerability exists in epan/reassemble.c where the generic block-sequence reassembly engine accumulates fragment lengths in a 32-bit unsigned integer without overflow checking. When the sum of fragment lengths exceeds UINT32_MAX, the accumulated value wraps to a smaller value, resulting in an undersized g_malloc() allocation. Subsequent code then copies all fragments at their full length into this undersized buffer, causing a heap buffer overflow. The attack requires processing >4 GiB of reassembled fragment data in a single sequence via SMTP, DICOM, or WebSocket protocols; this can occur through capture file dissection or live network monitoring. The crash is guaranteed (denial of service), though code execution is not demonstrated. Patches are available in Wireshark 4.6.8 and 4.4.18.
Affected products
- Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17
Timeline
- 2026-08-12: disclosed
- 2026-08-19: patched: Wireshark 4.6.8 and 4.4.18 released