CVE-2026-95388
Received Received - Intake

Sharkd Utility Denial of Service Vulnerability

Vulnerability report for CVE-2026-95388, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitLab Inc.

Description

Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
sharkd utility From 4.6.0 (inc) to 4.6.8 (inc)
sharkd utility From 4.4.0 (inc) to 4.4.18 (inc)
wireshark wireshark From 4.4.0 (inc) to 4.4.18 (inc)
wireshark wireshark From 4.6.0 (inc) to 4.6.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-95388 is a vulnerability in Sharkd, the backend component of Wireshark, that causes a crash due to an integer overflow during RTP resampling. An attacker can exploit this by providing a maliciously crafted SIP/SDP and RTP capture file with specific clock rates, leading to an undersized buffer allocation and out-of-bounds write in the Speex resampler. This results in a deterministic crash of the Sharkd worker process.

Detection Guidance

Detecting this vulnerability requires checking Wireshark versions. Run 'wireshark -v' or 'sharkd -v' to identify installed versions. If running 4.6.0 to 4.6.8 or 4.4.0 to 4.4.18, the system is vulnerable. Monitor Sharkd processes for crashes during RTP operations, especially when handling SIP/SDP and RTP capture files.

Impact Analysis

The vulnerability can cause a denial of service by crashing the Sharkd utility, which handles audio export operations in Wireshark. This disrupts legitimate Sharkd operations like loading capture files, analyzing RTP streams, or downloading RTP data. The impact is limited to worker termination and does not allow code execution or data theft.

Compliance Impact

This vulnerability causes a denial of service by crashing the Sharkd utility, which could disrupt network analysis operations. For GDPR, this may impact data processing activities requiring availability, potentially violating Article 32. For HIPAA, it could affect systems handling protected health information by causing service disruptions, though no data exposure is indicated.

Mitigation Strategies

Upgrade Wireshark to versions 4.6.9 or later, or 4.4.19 or later. Avoid processing untrusted capture files with Sharkd, particularly those containing SIP/SDP and RTP streams. Implement input validation for sample rates in RTP operations to prevent integer overflows.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95388. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart