CVE-2026-76884
Analyzed Analyzed - Analysis Complete

ERF File Parser Denial of Service Vulnerability

Vulnerability report for CVE-2026-76884, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-31

Assigner: GitLab Inc.

Description

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-31
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wireshark wireshark From 4.6.0 (inc) to 4.6.8 (exc)
wireshark wireshark From 4.4.0 (inc) to 4.4.18 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in ERF file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. It causes a crash in the parser, leading to service disruption.

Detection Guidance

This vulnerability is specific to ERF file parser crashes in versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18, leading to denial of service. Detection requires checking software versions and monitoring for crashes during ERF file processing. No direct commands are provided in the context.

Impact Analysis

The vulnerability allows attackers to cause a denial of service by crashing the ERF file parser. This could disrupt services relying on affected versions.

Compliance Impact

This vulnerability causes a denial of service through an ERF file parser crash, which may lead to system unavailability. While it does not directly impact data confidentiality or integrity, prolonged downtime could affect compliance with standards requiring timely data access, such as GDPR's right to access or HIPAA's availability requirements.

Mitigation Strategies

Update the affected ERF file parser software to versions outside the vulnerable range (4.6.0 to 4.6.7 and 4.4.0 to 4.4.18).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76884. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart