Memory Leak Vulnerability in IEEE C37.118 Synchrophasor Protocol Dissector by Wireshark
CVE-2026-95395

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-95395?

A memory leak vulnerability has been identified in the IEEE C37.118 Synchrophasor protocol dissector present in specific versions of Wireshark. This issue, which affects versions 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18, can lead to a denial of service due to excessive memory consumption when processing maliciously crafted data packets. It is crucial for users to update to the latest versions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Wireshark 4.6.0 < 4.6.9

Wireshark 4.4.0 < 4.4.19

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Liu Tianzhuo (刘天卓)
.