Denial of Service in Wireshark's MBIM Protocol Dissector
CVE-2026-95392

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-95392?

A vulnerability in Wireshark's MBIM protocol dissector exists across versions 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18, leading to a potential denial of service attack. Attackers can exploit this vulnerability, causing the application to crash when processing maliciously crafted MBIM packets. This deliberate interruption of service could impede network analysis, making it crucial for users of the affected versions to apply the necessary updates. Users are advised to follow best practices in network security and regularly check for updates to their software to mitigate such vulnerabilities.

Affected Version(s)

Wireshark 4.6.0 < 4.6.9

Wireshark 4.4.0 < 4.4.19

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mayank Jangid (OpenSec Intelligence)
.