Denial of Service Vulnerability in Toshiba File Parser by Wireshark
CVE-2026-96420

4.7MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-96420?

A vulnerability in the Toshiba file parser of Wireshark, present in versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18, can lead to a denial of service. This issue arises from improper handling of certain parsed files, which can cause the application to crash, disrupting network analysis activities. Users and organizations relying on Wireshark for packet analysis should be aware of this vulnerability and consider upgrading to a patched version to mitigate risks.

Affected Version(s)

Wireshark 4.6.0 < 4.6.9

Wireshark 4.4.0 < 4.4.19

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aisle Research (Dmitrijs Trizna, Luigino Camastra, Ze Sheng (O2Lab & TAMU), Igor Morgenstern)
.