CVE-2026-96420: 
Wireshark Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-96420 is a crash vulnerability in Wireshark's Toshiba file parser that can cause the application to crash when processing a malformed or crafted capture file. The flaw is tracked as Wireshark issue 21541 and was addressed in Wireshark version 4.6.9. The CVE status is currently listed as "Reserved," and the affected product is Wireshark by the Wireshark Foundation (Feedly, Wireshark Release Notes).

Détails techniques

The root cause of this vulnerability is a flaw in Wireshark's Toshiba file parser that fails to properly handle certain malformed input, leading to an application crash (likely a NULL pointer dereference or out-of-bounds read, consistent with CWE-125 or CWE-476). An attacker can exploit this by convincing a user to open a specially crafted Toshiba capture file within Wireshark, triggering the crash. Exploitation requires user interaction, as the victim must manually open the malicious file (Wireshark Release Notes, Feedly).

Impact

Successful exploitation results in a denial-of-service condition, causing Wireshark to crash and become unavailable. The primary impact is on availability; there is no evidence of code execution capability, and confidentiality and integrity impacts appear minimal. The vulnerability affects users who open untrusted Toshiba capture files with a vulnerable version of Wireshark (Wireshark Release Notes).

Exploitabilité

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-96420. The CVE status remains "Reserved," and there is no indication of inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploitation requires user interaction (opening a malicious file), which limits the practical attack surface (Feedly).

Étapes d’exploitation

  1. Craft malicious file: Create a specially crafted Toshiba capture file designed to trigger the parser flaw (issue 21541) in Wireshark's Toshiba file parser.
  2. Deliver the file: Distribute the malicious file to a target user via email attachment, file sharing, or social engineering, convincing them to open it in Wireshark.
  3. Trigger the crash: When the victim opens the file in a vulnerable version of Wireshark (prior to 4.6.9), the Toshiba file parser encounters the malformed input and crashes the application.
  4. Result: Wireshark crashes, causing a denial-of-service for the user's analysis session (Wireshark Release Notes).

Indicateurs de compromis

  • File System: Presence of unexpected or unsolicited .toshiba or similarly named capture files received from untrusted sources.
  • Logs: Wireshark crash reports or application error logs referencing the Toshiba file parser or issue 21541.
  • Process: Unexpected termination of the Wireshark process (wireshark.exe or wireshark) shortly after opening a capture file.

Atténuation et solutions de contournement

Users should upgrade to Wireshark version 4.6.9 or later, which contains the fix for this vulnerability (issue 21541) (Wireshark Release Notes). As a workaround, users should avoid opening Toshiba capture files from untrusted or unknown sources until the patch is applied. No additional configuration-based workarounds have been published.

Réactions de la communauté

The vulnerability was noted in the Wireshark 4.6.9 release announcement and covered by security news aggregators as part of a broader release fixing 19 vulnerabilities (cyberupdates365, Wireshark Announce). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE.

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Affecté

bookworm

wireshark

Affecté

sid

wireshark

Affecté

trixie

wireshark

Affecté

Ubuntu

Inconnu

bionic (esm-apps)

wireshark

Inconnu

devel

wireshark

Inconnu

focal (esm-apps)

wireshark

Inconnu

jammy

wireshark

Inconnu

jammy (esm-apps)

wireshark

Inconnu

noble

wireshark

Inconnu

noble (esm-apps)

wireshark

Inconnu

resolute

wireshark

Inconnu

RHEL / CentOS

Affecté

RHEL 8

Non affecté

RHEL 9

Non affecté

RHEL 10

wireshark.src

Affecté

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Wireshark Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NonNonSep 29, 2026
CVE-2026-96419MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités