CVE-2026-96415
Received Received - Intake

Catapult DCT2000 Protocol Dissector DoS Vulnerability

Vulnerability report for CVE-2026-96415, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitLab Inc.

Description

Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
catapult dct2000 From 4.6.0 (inc) to 4.6.8 (inc)
catapult dct2000 From 4.4.0 (inc) to 4.4.18 (inc)
wireshark wireshark From 4.4.0 (inc) to 4.6.8 (inc)
wireshark wireshark to 4.4.0 (exc)
wireshark wireshark to 4.6.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-96415 is a vulnerability in Wireshark's Catapult DCT2000 protocol dissector that causes crashes in versions 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. It occurs when a malformed packet or trace file triggers a crash in Wireshark, leading to a denial of service. The issue stems from a padding loop in the NR-UP dissector that writes past a 200-byte buffer due to unchecked length calculations from attacker-controlled input.

Detection Guidance

This vulnerability can be detected by checking if your Wireshark version is between 4.6.0 to 4.6.8 or 4.4.0 to 4.4.18. Use commands like 'wireshark -v' or 'tshark -v' to check the version. If vulnerable, opening a malformed DCT2000 packet trace file or receiving a malicious packet may cause Wireshark to crash.

Impact Analysis

This vulnerability can cause Wireshark to crash when processing malicious network traffic or opening corrupted packet files. Users may experience unexpected shutdowns of Wireshark, disrupting network analysis tasks. While no known exploits exist, the crash could lead to lost work or downtime during investigations.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a denial-of-service issue in Wireshark's protocol dissector. It may indirectly impact compliance if Wireshark is used in environments where availability is critical for data processing or monitoring, potentially violating availability requirements under these standards.

Mitigation Strategies

Upgrade Wireshark to version 4.6.9 or later, or 4.4.19 or later. Avoid opening untrusted packet capture files, especially those with DCT2000 format. Monitor Wireshark's official mailing lists for updates and best practices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96415. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart