CVE-2026-96422: 
Wireshark Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-96422 is a vulnerability in Wireshark's Frame protocol metadissector that can cause a crash when parsing Frame protocol data. The CVE is currently in "Reserved" status, and the affected product is Wireshark. Based on available Feedly threat intelligence, fixed versions appear to include Wireshark 4.6.9 and 4.4.19, released in September 2026. No CVSS score has been publicly assigned at this time (Feedly, Wireshark 4.6.9 Release Notes).

Détails techniques

The vulnerability resides in Wireshark's Frame protocol metadissector, which is responsible for parsing Frame protocol metadata during packet capture analysis. A malformed or specially crafted packet capture file could trigger the crash condition when the dissector processes Frame protocol data. The root cause is likely an improper input validation or unhandled edge case in the dissector logic (CWE-20 or CWE-125), though the full technical details have not been publicly disclosed given the CVE's reserved status (Feedly, Wireshark 4.6.9 Release Notes).

Impact

Successful exploitation of this vulnerability results in a crash of the Wireshark application, causing a denial of service to the analyst or user processing the affected packet capture. Since Wireshark typically runs with user-level privileges, the impact is generally limited to availability of the application rather than system-wide compromise. There is no current evidence of code execution capability, data exfiltration risk, or lateral movement potential associated with this vulnerability (Feedly).

Exploitabilité

There are no known public proof-of-concept exploits, exploit kits, or evidence of in-the-wild exploitation for CVE-2026-96422 at this time. The CVE remains in "Reserved" status, and no EPSS score or CISA KEV catalog listing has been identified. Exploitation would require an attacker to convince a Wireshark user to open a maliciously crafted packet capture file, limiting the practical attack surface (Feedly).

Étapes d’exploitation

  1. Craft malicious capture file: An attacker creates a specially crafted packet capture file (e.g., .pcap or .pcapng) containing malformed Frame protocol metadata designed to trigger the crash condition in Wireshark's metadissector.
  2. Deliver the file: The attacker delivers the malicious capture file to a target Wireshark user via email attachment, file sharing, or by hosting it on a website and enticing the user to download it.
  3. Trigger the vulnerability: The victim opens the malicious capture file in a vulnerable version of Wireshark, causing the Frame protocol metadissector to parse the malformed data.
  4. Application crash: Wireshark crashes, resulting in a denial of service for the analyst. Any unsaved work or ongoing capture sessions may be lost (Feedly).

Indicateurs de compromis

  • File System: Presence of unexpected or unsolicited .pcap or .pcapng files received via email or downloaded from untrusted sources.
  • Logs: Wireshark crash reports or core dump files generated in the user's home directory or application data folder following the opening of a packet capture file.
  • Process: Unexpected termination of the Wireshark process (wireshark, tshark) without user-initiated closure.

Atténuation et solutions de contournement

Users should upgrade to Wireshark 4.6.9 or 4.4.19, which appear to contain fixes for this vulnerability based on their September 2026 release timing. As a workaround, users should avoid opening packet capture files from untrusted or unknown sources. Organizations should ensure Wireshark installations are kept up to date via their standard patch management processes (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes).

Réactions de la communauté

Coverage of CVE-2026-96422 has been limited, consistent with its status as one of multiple vulnerabilities addressed in the Wireshark 4.6.9 release. A security news outlet noted that Wireshark 4.6.9 fixes 19 vulnerabilities in total, suggesting this CVE is part of a broader patch batch rather than a standalone critical issue (CyberUpdates365).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Affecté

bookworm

wireshark

Affecté

sid

wireshark

Affecté

trixie

wireshark

Affecté

Ubuntu

Inconnu

bionic (esm-apps)

wireshark

Inconnu

devel

wireshark

Inconnu

focal (esm-apps)

wireshark

Inconnu

jammy

wireshark

Inconnu

jammy (esm-apps)

wireshark

Inconnu

noble

wireshark

Inconnu

noble (esm-apps)

wireshark

Inconnu

resolute

wireshark

Inconnu

RHEL / CentOS

Affecté

RHEL 8

Non affecté

RHEL 9

Non affecté

RHEL 10

wireshark.src

Affecté

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Wireshark Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NonNonSep 29, 2026
CVE-2026-96419MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NonNonSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NonNonSep 29, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités