Junglewise Threat Intelligence

CVE-2026-76920: Wireshark 3GPP log file parser buffer overflow

CVE-2026-76920 · Severity: medium · CVSS 4.7 · Published 2026-08-19

Vendors: Wireshark Foundation.

Executive brief

Wireshark is a widely-used network traffic analysis tool. A flaw in its 3GPP protocol log parser allows a crafted log file to write one byte past the allocated packet buffer, potentially causing the application to crash or enabling heap corruption. An attacker could exploit this by distributing a malicious capture file.

Technical details

The vulnerability is a one-byte heap buffer overflow (CWE-787) in the 3GPP log file decoder (wiretap/log3gpp.c). The `build_packet_record()` function reserves space for decoded hexadecimal payload but uses an inclusive loop bound (`<=`), causing it to write one extra byte beyond the allocated buffer. The flaw affects versions 4.6.0–4.6.7 and 4.4.0–4.4.17. An attacker can craft a specially-formed 3GPP log capture file that triggers this overflow when opened in Wireshark (tshark). While the PoC demonstrates deterministic crashes via AddressSanitizer, heap corruption could potentially lead to code execution under certain memory conditions. Patches are available in versions 4.6.8, 4.4.18, and later.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17

Timeline

  • 2026-08-12: disclosed
  • 2026-08-19: advisory: CVE-2026-76920 published
  • 2026-08-12: patched: Fixed in versions 4.6.8 and 4.4.18

References