CMS Protocol Dissector Vulnerability in Wireshark
CVE-2026-76921
5.5MEDIUM
What is CVE-2026-76921?
A vulnerability in the CMS protocol dissector of Wireshark causes crashes in specific versions, leading to a denial of service condition. Users running Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 are at risk as this flaw can be exploited through crafted packets, rendering the application unresponsive. It is crucial for users of affected versions to apply patches as they become available to mitigate potential disruptions.
Affected Version(s)
Wireshark 4.6.0 < 4.6.8
Wireshark 4.4.0 < 4.4.18
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aisle Research (Dmitrijs Trizna, Luigino Camastra, Ze Sheng (O2Lab & TAMU), Igor Morgenstern)