Junglewise Threat Intelligence

CVE-2026-76929: Wireshark pcapng file parser heap out-of-bounds read

CVE-2026-76929 · Severity: medium · CVSS 4.7 · Published 2026-08-19

Technologies: Wireshark. Vendors: Wireshark.

Executive brief

Wireshark is a network traffic analysis tool used to inspect and troubleshoot network communications. A flaw in its pcapng file parser can be triggered by opening a malformed packet capture file, causing the application to crash and denying service to analysts who depend on it for network diagnostics. An attacker could distribute a crafted capture file to cause denial of service.

Technical details

The vulnerability is a heap-based out-of-bounds read in the Netflix pcapng TCPINFO custom option parser (wiretap/pcapng-netflix-custom.c). The parser validates only a 4-byte subtype field but then unconditionally performs two 8-byte timestamp reads without checking payload length. A malformed pcapng custom block with an empty TCPINFO payload triggers an 8-byte out-of-bounds read, causing a crash via AddressSanitizer detection or direct heap corruption. No authentication or user interaction is required beyond opening the malicious file; the crash occurs during initial packet capture parsing before any dissection. Patches are available in Wireshark 4.6.8 and 4.4.18+, which add length validation before the timestamp reads.

Affected products

  • Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17

Timeline

  • 2026-08-12: disclosed
  • 2026-08-19: patched: Fixed in Wireshark 4.6.8, 4.4.18

References

Related threats