Junglewise Threat Intelligence

CVE-2026-76924: Wireshark Kerberos dissector heap buffer overflow

CVE-2026-76924 · Severity: medium · CVSS 5.5 · Published 2026-08-19

Technologies: Wireshark. Vendors: Wireshark.

Executive brief

Wireshark is a widely used network analysis tool that includes support for decoding the Kerberos authentication protocol. A malformed Kerberos credential packet can trigger an out-of-bounds read in the dissector's key formatting logic, causing Wireshark or TShark to crash. An attacker can exploit this by injecting a crafted packet on the network or tricking a user into opening a malicious packet capture file, resulting in denial of service.

Technical details

The vulnerability is a heap buffer overflow (CWE-125) in the Kerberos dissector's encryption key handling code, specifically in the learned-key formatter in packet-kerberos-template.c and packet-kerberos.c. When processing a plaintext EncKrbCredPart structure with a short EncryptionKey (1–3 bytes), the dissector correctly copies the key bytes into retained storage but then attempts to format a four-byte hexadecimal preview directly from the original input buffer without bounds checking. This causes an out-of-bounds read beyond the allocated buffer. The attack requires only a crafted plaintext Kerberos credential sent over UDP/88 (no authentication, valid key, or successful decryption needed). An instrumented Wireshark or TShark instance will crash; behavior in release builds depends on adjacent allocator contents. Patches are available in Wireshark 4.6.8, 4.4.18, and later.

Affected products

  • Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17

Timeline

  • 2026-08-12: disclosed
  • 2026-08-19: patched: Fixed in versions 4.6.8, 4.4.18, and later

References

Related threats