Executive brief
Wireshark is a widely-used network packet analyzer that includes support for the ESS (Estimated System Services) security protocol. A flaw in its ESS dissector can cause the application to crash when processing malformed packets, disrupting network troubleshooting and analysis operations. An attacker could exploit this by sending a crafted packet over the network or through a malicious packet capture file.
Technical details
The vulnerability is a use of an uninitialized variable (CWE-457) in the ESS protocol dissector code. Three BIT STRING overrides in the dissector template (ess.cnf) declare a pointer variable without initialization, then pass it to post-processing functions regardless of whether the BER bitstring parsing succeeded. When the dissect_ber_bitstring() helper encounters a malformed BIT STRING (e.g., zero-length), it returns early without assigning the output pointer, leaving it uninitialized. The subsequent call to ess_dissect_attribute_flags() dereferences this uninitialized pointer through TVB APIs, causing a crash or memory access violation. The vulnerability is reachable through registered OID dissectors for CMS/S/MIME content in untrusted network captures or packet files. Patches are available in Wireshark 4.6.8, 4.4.18, and later.
Affected products
- Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17
Timeline
- 2026-08-12: disclosed
- 2026: patched: Fixed in versions 4.6.8 and 4.4.18