CVE-2026-76929
Analyzed Analyzed - Analysis Complete

Pcapng Parser Crash Causes Denial of Service in Wireshark

Vulnerability report for CVE-2026-76929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-31

Assigner: GitLab Inc.

Description

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-31
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wireshark wireshark From 4.6.0 (inc) to 4.6.8 (exc)
wireshark wireshark From 4.4.0 (inc) to 4.4.18 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in the pcapng file parser affecting versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. It causes the parser to crash when processing certain pcapng files, leading to service disruption.

Detection Guidance

This vulnerability is specific to a pcapng file parser crash in versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18, leading to denial of service. Detection involves checking the installed version of the affected software. Use commands like 'dpkg -l | grep <package-name>' on Debian-based systems or 'rpm -qa | grep <package-name>' on RPM-based systems to verify the version.

Impact Analysis

The vulnerability allows an attacker to cause a denial of service by crashing the pcapng file parser. This could disrupt network monitoring, analysis, or security tools that rely on parsing pcapng files.

Compliance Impact

This vulnerability causes a denial of service through a pcapng file parser crash, which may disrupt system availability. While not directly tied to data confidentiality or integrity, prolonged downtime could impact compliance with standards requiring system availability, such as HIPAA for healthcare systems or GDPR for service continuity. However, specific compliance impacts depend on system context and mitigations.

Mitigation Strategies

Update Wireshark to versions 4.6.8 or later for the 4.6.x branch, or 4.4.19 or later for the 4.4.x branch to patch the pcapng file parser crash vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76929. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart