
PEACH
Un cadre d’isolation des locataires
CVE-2026-96422 is a vulnerability in Wireshark's Frame protocol metadissector that can cause a crash when parsing Frame protocol data. The CVE is currently in "Reserved" status, and the affected product is Wireshark. Based on available Feedly threat intelligence, fixed versions appear to include Wireshark 4.6.9 and 4.4.19, released in September 2026. No CVSS score has been publicly assigned at this time (Feedly, Wireshark 4.6.9 Release Notes).
The vulnerability resides in Wireshark's Frame protocol metadissector, which is responsible for parsing Frame protocol metadata during packet capture analysis. A malformed or specially crafted packet capture file could trigger the crash condition when the dissector processes Frame protocol data. The root cause is likely an improper input validation or unhandled edge case in the dissector logic (CWE-20 or CWE-125), though the full technical details have not been publicly disclosed given the CVE's reserved status (Feedly, Wireshark 4.6.9 Release Notes).
Successful exploitation of this vulnerability results in a crash of the Wireshark application, causing a denial of service to the analyst or user processing the affected packet capture. Since Wireshark typically runs with user-level privileges, the impact is generally limited to availability of the application rather than system-wide compromise. There is no current evidence of code execution capability, data exfiltration risk, or lateral movement potential associated with this vulnerability (Feedly).
There are no known public proof-of-concept exploits, exploit kits, or evidence of in-the-wild exploitation for CVE-2026-96422 at this time. The CVE remains in "Reserved" status, and no EPSS score or CISA KEV catalog listing has been identified. Exploitation would require an attacker to convince a Wireshark user to open a maliciously crafted packet capture file, limiting the practical attack surface (Feedly).
.pcap or .pcapng) containing malformed Frame protocol metadata designed to trigger the crash condition in Wireshark's metadissector..pcap or .pcapng files received via email or downloaded from untrusted sources.wireshark, tshark) without user-initiated closure.Users should upgrade to Wireshark 4.6.9 or 4.4.19, which appear to contain fixes for this vulnerability based on their September 2026 release timing. As a workaround, users should avoid opening packet capture files from untrusted or unknown sources. Organizations should ensure Wireshark installations are kept up to date via their standard patch management processes (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes).
Coverage of CVE-2026-96422 has been limited, consistent with its status as one of multiple vulnerabilities addressed in the Wireshark 4.6.9 release. A security news outlet noted that Wireshark 4.6.9 fixes 19 vulnerabilities in total, suggesting this CVE is part of a broader patch batch rather than a standalone critical issue (CyberUpdates365).
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bionic (esm-apps)
wireshark
devel
wireshark
focal (esm-apps)
wireshark
jammy
wireshark
jammy (esm-apps)
wireshark
noble
wireshark
noble (esm-apps)
wireshark
resolute
wireshark
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."