SB2026092420 - Multiple vulnerabilities in Wireshark
Published: September 24, 2026 Updated: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 19 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2026-95388)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified error in the sharkd utility when using the utility. A remote attacker can use the sharkd utility to cause a denial of service.
2) Input validation error (CVE-ID: CVE-2026-95391)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the ZigBee ZCL protocol dissector when processing malformed packets. A remote attacker can inject a malformed packet onto the wire or convince a user to open a malformed packet trace file to cause a denial of service.
3) Input validation error (CVE-ID: CVE-2026-95389)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the SCTP protocol dissector when processing a malformed SCTP packet. A remote attacker can inject a malformed packet onto the wire to cause a denial of service.
The issue can also be triggered when a user reads a malformed packet trace file.
4) Infinite loop (CVE-ID: CVE-2026-95386)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in the TTL file parser when parsing a malformed packet trace file. A remote attacker can trick the victim into opening a malformed packet trace file to cause a denial of service.
5) Input validation error (CVE-ID: CVE-2026-95390)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the PEAK CAN TRC file parser when parsing a malformed packet trace file. A remote attacker can craft a malformed packet trace file and convince a user to open it to cause a denial of service.
6) Memory leak (CVE-ID: CVE-2026-95395)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause excessive CPU resource consumption.
The vulnerability exists due to a memory leak in the IEEE C37.118 Synchrophasor protocol dissector when processing a malformed IEEE C37.118 Synchrophasor packet. A remote attacker can inject a malformed packet onto the wire to cause excessive CPU resource consumption.
The issue may also be triggered when a user reads a malformed packet trace file.
7) Input validation error (CVE-ID: CVE-2026-95387)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the SPDY protocol dissector when dissecting malformed SPDY packets. A remote attacker can inject a malformed packet onto the wire or convince a victim to read a malformed packet trace file to cause a denial of service.
8) Infinite loop (CVE-ID: CVE-2026-95394)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uncontrolled loop in the Microsoft Network Monitor file parser when parsing a malformed packet trace file. A remote attacker can trick the victim into opening a malformed packet trace file to cause a denial of service.
9) Improper handling of exceptional conditions (CVE-ID: CVE-2026-95393)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of malformed packets in the CSN.1 protocol dissector when processing captured network traffic. A remote attacker can inject a malformed packet onto the wire to cause a denial of service.
The issue can also be triggered when a user opens a malformed packet trace file.
10) Input validation error (CVE-ID: CVE-2026-95392)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the MBIM protocol dissector when processing malformed MBIM packets. A remote attacker can inject a malformed packet onto the wire or convince someone to read a malformed packet trace file to cause a denial of service.
11) Input validation error (CVE-ID: CVE-2026-96415)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the Catapult DCT2000 protocol dissector when processing a malformed packet. A remote attacker can inject a malformed packet onto the wire to cause a denial of service.
The issue can also be triggered by convincing someone to read a malformed packet trace file.
12) Input validation error (CVE-ID: CVE-2026-96422)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the Frame protocol metadissector when processing malformed packets. A remote attacker can inject a malformed packet onto the wire or convince someone to read a malformed packet trace file to cause a denial of service.
Reading a malformed packet trace file requires user interaction.
13) Infinite loop (CVE-ID: CVE-2026-96421)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop and memory leak in the USB HID protocol dissector when processing a malformed USB HID packet. A remote attacker can inject a malformed packet onto the local network to cause a denial of service.
User interaction is required when exploitation is performed through a malformed packet trace file.
14) Input validation error (CVE-ID: CVE-2026-96417)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the RF4CE protocol dissector when processing malformed RF4CE packets. A remote attacker can inject a malformed RF4CE packet onto the wire to cause a denial of service.
Exploitation may also involve convincing someone to read a malformed packet trace file.
15) Input validation error (CVE-ID: CVE-2026-96420)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the Toshiba file parser when parsing a malformed packet trace file. A remote attacker can trick the victim into opening a crafted packet trace file to cause a denial of service.
16) Input validation error (CVE-ID: CVE-2026-96419)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to an unspecified flaw in profile import functionality when importing a crafted configuration profile. A remote attacker can trick a victim into importing a malformed configuration profile to execute arbitrary code or cause a denial of service.
User interaction is required to import the crafted configuration profile.
17) Infinite loop (CVE-ID: CVE-2026-96418)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in the TIFF protocol dissector when parsing a malformed packet trace file. A remote attacker can trick a victim into opening a malformed packet trace file to cause a denial of service.
Malformed packets injected onto the wire can also trigger the issue.
18) Input validation error (CVE-ID: CVE-2026-96423)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the X11 protocol dissector when dissecting malformed X11 packets or reading malformed packet trace files. A remote attacker can inject a malformed packet onto the wire or convince someone to read a malformed packet trace file to cause a denial of service.
19) Input validation error (CVE-ID: CVE-2026-96416)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified error in the IEEE 802.11 protocol dissector when processing malformed IEEE 802.11 packets. A remote attacker can inject a malformed packet onto the wire to cause a denial of service.
Exploitation may also be possible by convincing a victim to read a malformed packet trace file.
Remediation
Install update from vendor's website.
References
- https://www.wireshark.org/security/wnpa-sec-2026-101.html
- https://gitlab.com/wireshark/wireshark/-/issues/21545
- https://www.wireshark.org/security/wnpa-sec-2026-92.html
- https://gitlab.com/wireshark/wireshark/-/merge_requests/26096
- https://www.wireshark.org/security/wnpa-sec-2026-93.html
- https://gitlab.com/wireshark/wireshark/-/issues/21481
- https://www.wireshark.org/security/wnpa-sec-2026-94.html
- https://gitlab.com/wireshark/wireshark/-/issues/21501
- https://www.wireshark.org/security/wnpa-sec-2026-95.html
- https://gitlab.com/wireshark/wireshark/-/issues/21503
- https://www.wireshark.org/security/wnpa-sec-2026-96.html
- https://gitlab.com/wireshark/wireshark/-/issues/21492
- https://www.wireshark.org/security/wnpa-sec-2026-97.html
- https://gitlab.com/wireshark/wireshark/-/issues/21487
- https://www.wireshark.org/security/wnpa-sec-2026-98.html
- https://gitlab.com/wireshark/wireshark/-/commit/5cc3a15d3d
- https://www.wireshark.org/security/wnpa-sec-2026-99.html
- https://gitlab.com/wireshark/wireshark/-/commit/7379ffcb0f
- https://www.wireshark.org/security/wnpa-sec-2026-100.html
- https://gitlab.com/wireshark/wireshark/-/issues/21549
- https://www.wireshark.org/security/wnpa-sec-2026-110.html
- https://gitlab.com/wireshark/wireshark/-/issues/21589
- https://www.wireshark.org/security/wnpa-sec-2026-102.html
- https://gitlab.com/wireshark/wireshark/-/issues/21525
- https://www.wireshark.org/security/wnpa-sec-2026-103.html
- https://gitlab.com/wireshark/wireshark/-/commit/857d9b98e9
- https://www.wireshark.org/security/wnpa-sec-2026-104.html
- https://gitlab.com/wireshark/wireshark/-/issues/21574
- https://www.wireshark.org/security/wnpa-sec-2026-105.html
- https://gitlab.com/wireshark/wireshark/-/commit/9f54bc5a6b
- https://www.wireshark.org/security/wnpa-sec-2026-106.html
- https://gitlab.com/wireshark/wireshark/-/issues/21553
- https://www.wireshark.org/security/wnpa-sec-2026-107.html
- https://gitlab.com/wireshark/wireshark/-/issues/21565
- https://www.wireshark.org/security/wnpa-sec-2026-108.html
- https://gitlab.com/wireshark/wireshark/-/issues/21563
- https://www.wireshark.org/security/wnpa-sec-2026-109.html
- https://gitlab.com/wireshark/wireshark/-/issues/21564