
PEACH
Un cadre d’isolation des locataires
CVE-2026-96420 is a crash vulnerability in Wireshark's Toshiba file parser that can cause the application to crash when processing a malformed or crafted capture file. The flaw is tracked as Wireshark issue 21541 and was addressed in Wireshark version 4.6.9. The CVE status is currently listed as "Reserved," and the affected product is Wireshark by the Wireshark Foundation (Feedly, Wireshark Release Notes).
The root cause of this vulnerability is a flaw in Wireshark's Toshiba file parser that fails to properly handle certain malformed input, leading to an application crash (likely a NULL pointer dereference or out-of-bounds read, consistent with CWE-125 or CWE-476). An attacker can exploit this by convincing a user to open a specially crafted Toshiba capture file within Wireshark, triggering the crash. Exploitation requires user interaction, as the victim must manually open the malicious file (Wireshark Release Notes, Feedly).
Successful exploitation results in a denial-of-service condition, causing Wireshark to crash and become unavailable. The primary impact is on availability; there is no evidence of code execution capability, and confidentiality and integrity impacts appear minimal. The vulnerability affects users who open untrusted Toshiba capture files with a vulnerable version of Wireshark (Wireshark Release Notes).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-96420. The CVE status remains "Reserved," and there is no indication of inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploitation requires user interaction (opening a malicious file), which limits the practical attack surface (Feedly).
.toshiba or similarly named capture files received from untrusted sources.wireshark.exe or wireshark) shortly after opening a capture file.Users should upgrade to Wireshark version 4.6.9 or later, which contains the fix for this vulnerability (issue 21541) (Wireshark Release Notes). As a workaround, users should avoid opening Toshiba capture files from untrusted or unknown sources until the patch is applied. No additional configuration-based workarounds have been published.
The vulnerability was noted in the Wireshark 4.6.9 release announcement and covered by security news aggregators as part of a broader release fixing 19 vulnerabilities (cyberupdates365, Wireshark Announce). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE.
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bionic (esm-apps)
wireshark
devel
wireshark
focal (esm-apps)
wireshark
jammy
wireshark
jammy (esm-apps)
wireshark
noble
wireshark
noble (esm-apps)
wireshark
resolute
wireshark
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."