
PEACH
Un cadre d’isolation des locataires
CVE-2026-96419 is a vulnerability in Wireshark where the profile import functionality can be abused to cause a crash and potentially allow code execution. The CVE is currently in "Reserved" status with limited published technical details. It affects Wireshark (vendor: Wireshark Foundation), and patches appear to have been included in Wireshark 4.6.9 and 4.4.19, which together address 19 security vulnerabilities (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes). The estimated CVSS severity is HIGH (Feedly).
The vulnerability resides in Wireshark's profile import functionality, which can be abused — potentially via a maliciously crafted profile file — to trigger a crash and possibly achieve code execution. This is consistent with a memory corruption or improper input validation issue (likely CWE-20 or a related memory safety weakness), though the exact CWE has not been officially published given the CVE's reserved status. An attacker would need to convince a user to import a malicious Wireshark profile, making this a user-interaction-dependent, local or social-engineering-based attack vector (Feedly, Heise Security).
Successful exploitation could result in a Wireshark application crash (denial of service) or, in a worst-case scenario, arbitrary code execution on the analyst's workstation. Because Wireshark is commonly used by network engineers and security analysts — often on sensitive internal systems — code execution via a malicious profile file could expose credentials, network captures, or enable lateral movement within an organization (Heise Security, CyberSecurityNews).
As of the time of reporting, the CVE remains in "Reserved" status with no published PoC exploit code and no confirmed in-the-wild exploitation (Feedly). Exploitation requires user interaction — specifically, a user must be tricked into importing a malicious Wireshark profile. No EPSS score or CISA KEV catalog entry has been identified for this CVE. The attack surface is limited to users who accept and import untrusted Wireshark profile files (Heise Security).
Users should upgrade to Wireshark 4.6.9 or 4.4.19, which include fixes for this and 18 other security vulnerabilities (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes). As a workaround, users should avoid importing Wireshark profiles from untrusted or unknown sources. Organizations should enforce policies restricting the import of externally sourced Wireshark profiles on analyst workstations (Heise Security).
Security media outlets including CyberSecurityNews, Heise Security, and Linuxiac covered the Wireshark 4.6.9 release, highlighting the profile import vulnerability as a notable risk because it could allow malware delivery via seemingly benign configuration files (Heise Security, CyberSecurityNews, Linuxiac). Heise Security specifically noted that profile imports could "carry malware," drawing attention to the social engineering risk for security professionals who routinely share Wireshark configurations.
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bionic (esm-apps)
wireshark
devel
wireshark
focal (esm-apps)
wireshark
jammy
wireshark
jammy (esm-apps)
wireshark
noble
wireshark
noble (esm-apps)
wireshark
resolute
wireshark
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."