Junglewise Threat Intelligence

CVE-2026-76919: Wireshark ESS protocol dissector crash via uninitialized pointer

CVE-2026-76919 · Severity: medium · CVSS 5.3 · Published 2026-08-19

Technologies: Wireshark. Vendors: Wireshark.

Executive brief

Wireshark is a widely-used network packet analyzer that includes support for the ESS (Estimated System Services) security protocol. A flaw in its ESS dissector can cause the application to crash when processing malformed packets, disrupting network troubleshooting and analysis operations. An attacker could exploit this by sending a crafted packet over the network or through a malicious packet capture file.

Technical details

The vulnerability is a use of an uninitialized variable (CWE-457) in the ESS protocol dissector code. Three BIT STRING overrides in the dissector template (ess.cnf) declare a pointer variable without initialization, then pass it to post-processing functions regardless of whether the BER bitstring parsing succeeded. When the dissect_ber_bitstring() helper encounters a malformed BIT STRING (e.g., zero-length), it returns early without assigning the output pointer, leaving it uninitialized. The subsequent call to ess_dissect_attribute_flags() dereferences this uninitialized pointer through TVB APIs, causing a crash or memory access violation. The vulnerability is reachable through registered OID dissectors for CMS/S/MIME content in untrusted network captures or packet files. Patches are available in Wireshark 4.6.8, 4.4.18, and later.

Affected products

  • Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17

Timeline

  • 2026-08-12: disclosed
  • 2026: patched: Fixed in versions 4.6.8 and 4.4.18

References

Related threats