Executive brief
Wireshark is a widely used network analysis tool that includes support for decoding the Kerberos authentication protocol. A malformed Kerberos credential packet can trigger an out-of-bounds read in the dissector's key formatting logic, causing Wireshark or TShark to crash. An attacker can exploit this by injecting a crafted packet on the network or tricking a user into opening a malicious packet capture file, resulting in denial of service.
Technical details
The vulnerability is a heap buffer overflow (CWE-125) in the Kerberos dissector's encryption key handling code, specifically in the learned-key formatter in packet-kerberos-template.c and packet-kerberos.c. When processing a plaintext EncKrbCredPart structure with a short EncryptionKey (1–3 bytes), the dissector correctly copies the key bytes into retained storage but then attempts to format a four-byte hexadecimal preview directly from the original input buffer without bounds checking. This causes an out-of-bounds read beyond the allocated buffer. The attack requires only a crafted plaintext Kerberos credential sent over UDP/88 (no authentication, valid key, or successful decryption needed). An instrumented Wireshark or TShark instance will crash; behavior in release builds depends on adjacent allocator contents. Patches are available in Wireshark 4.6.8, 4.4.18, and later.
Affected products
- Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17
Timeline
- 2026-08-12: disclosed
- 2026-08-19: patched: Fixed in versions 4.6.8, 4.4.18, and later