CVE-2026-96419: 
Wireshark Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-96419 is a vulnerability in Wireshark where the profile import functionality can be abused to cause a crash and potentially allow code execution. The CVE is currently in "Reserved" status with limited published technical details. It affects Wireshark (vendor: Wireshark Foundation), and patches appear to have been included in Wireshark 4.6.9 and 4.4.19, which together address 19 security vulnerabilities (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes). The estimated CVSS severity is HIGH (Feedly).

Détails techniques

The vulnerability resides in Wireshark's profile import functionality, which can be abused — potentially via a maliciously crafted profile file — to trigger a crash and possibly achieve code execution. This is consistent with a memory corruption or improper input validation issue (likely CWE-20 or a related memory safety weakness), though the exact CWE has not been officially published given the CVE's reserved status. An attacker would need to convince a user to import a malicious Wireshark profile, making this a user-interaction-dependent, local or social-engineering-based attack vector (Feedly, Heise Security).

Impact

Successful exploitation could result in a Wireshark application crash (denial of service) or, in a worst-case scenario, arbitrary code execution on the analyst's workstation. Because Wireshark is commonly used by network engineers and security analysts — often on sensitive internal systems — code execution via a malicious profile file could expose credentials, network captures, or enable lateral movement within an organization (Heise Security, CyberSecurityNews).

Exploitabilité

As of the time of reporting, the CVE remains in "Reserved" status with no published PoC exploit code and no confirmed in-the-wild exploitation (Feedly). Exploitation requires user interaction — specifically, a user must be tricked into importing a malicious Wireshark profile. No EPSS score or CISA KEV catalog entry has been identified for this CVE. The attack surface is limited to users who accept and import untrusted Wireshark profile files (Heise Security).

Étapes d’exploitation

  1. Craft malicious profile: An attacker creates a specially crafted Wireshark profile file designed to trigger a memory corruption or input validation flaw in the profile import parser.
  2. Deliver the profile: The attacker distributes the malicious profile via email, file sharing, or a compromised repository, targeting Wireshark users (e.g., network analysts or security researchers).
  3. Social engineering: The attacker convinces the target to import the profile into Wireshark (e.g., by presenting it as a useful configuration or custom dissector profile).
  4. Trigger the vulnerability: When the victim imports the profile through Wireshark's profile import functionality, the malformed data triggers a crash or memory corruption condition.
  5. Achieve code execution: If the memory corruption is exploitable, the attacker's payload executes in the context of the Wireshark process on the victim's workstation, potentially enabling further compromise (Heise Security, CyberSecurityNews).

Atténuation et solutions de contournement

Users should upgrade to Wireshark 4.6.9 or 4.4.19, which include fixes for this and 18 other security vulnerabilities (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes). As a workaround, users should avoid importing Wireshark profiles from untrusted or unknown sources. Organizations should enforce policies restricting the import of externally sourced Wireshark profiles on analyst workstations (Heise Security).

Réactions de la communauté

Security media outlets including CyberSecurityNews, Heise Security, and Linuxiac covered the Wireshark 4.6.9 release, highlighting the profile import vulnerability as a notable risk because it could allow malware delivery via seemingly benign configuration files (Heise Security, CyberSecurityNews, Linuxiac). Heise Security specifically noted that profile imports could "carry malware," drawing attention to the social engineering risk for security professionals who routinely share Wireshark configurations.

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Affecté

bookworm

wireshark

Affecté

sid

wireshark

Affecté

trixie

wireshark

Affecté

Ubuntu

Inconnu

bionic (esm-apps)

wireshark

Inconnu

devel

wireshark

Inconnu

focal (esm-apps)

wireshark

Inconnu

jammy

wireshark

Inconnu

jammy (esm-apps)

wireshark

Inconnu

noble

wireshark

Inconnu

noble (esm-apps)

wireshark

Inconnu

resolute

wireshark

Inconnu

RHEL / CentOS

Affecté

RHEL 8

Non affecté

RHEL 9

Non affecté

RHEL 10

wireshark.src

Affecté

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Wireshark Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NonNonSep 29, 2026
CVE-2026-96419MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités