CMS Protocol Dissector Vulnerability in Wireshark
CVE-2026-76921

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76921?

A vulnerability in the CMS protocol dissector of Wireshark causes crashes in specific versions, leading to a denial of service condition. Users running Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 are at risk as this flaw can be exploited through crafted packets, rendering the application unresponsive. It is crucial for users of affected versions to apply patches as they become available to mitigate potential disruptions.

Affected Version(s)

Wireshark 4.6.0 < 4.6.8

Wireshark 4.4.0 < 4.4.18

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aisle Research (Dmitrijs Trizna, Luigino Camastra, Ze Sheng (O2Lab & TAMU), Igor Morgenstern)
.