CVE-2026-0961
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-0961 is an out-of-bounds write vulnerability in the BLF (Binary Logging Format) file parser of Wireshark that allows denial of service via application crash. It affects Wireshark versions 4.4.0 through 4.4.12 and 4.6.0 through 4.6.2. The vulnerability was disclosed on January 14, 2026, with NVD initial analysis completed on January 21, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) per NVD, and 5.5 (Medium) per the CNA (GitLab Inc.) (Wireshark Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in Wireshark's BLF file parser component. An attacker can craft a malicious BLF file that, when opened by a victim, triggers an out-of-bounds write operation causing the application to crash. Exploitation requires user interaction — specifically, a user must open a specially crafted BLF file — and the attack vector is local (per the CNA) or network-based if the file is delivered remotely (per NVD enrichment). A proof-of-concept issue demonstrating the crash is publicly available on the Wireshark GitLab issue tracker (GitLab Issue).

Impact

Successful exploitation results in a Wireshark application crash, causing a denial of service with high availability impact. There is no confidentiality or integrity impact — the vulnerability cannot be used to exfiltrate data or modify system state. The scope is limited to the Wireshark process itself, with no evidence of lateral movement potential or privilege escalation (Wireshark Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Craft malicious BLF file: Create a specially crafted BLF (Binary Logging Format) file designed to trigger an out-of-bounds write in Wireshark's BLF parser, referencing the public GitLab issue (#20880) for structural details.
  2. Deliver the file: Distribute the malicious BLF file to a target user via email attachment, file share, or social engineering — since user interaction is required to open the file.
  3. Trigger the crash: Convince the target user to open the crafted BLF file in a vulnerable version of Wireshark (4.4.0–4.4.12 or 4.6.0–4.6.2).
  4. Achieve denial of service: Upon parsing the malicious file, Wireshark performs an out-of-bounds write, causing the application to crash and become unavailable (GitLab Issue, Wireshark Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .blf files in user download directories, email attachments, or shared network folders.
  • Logs: Wireshark crash reports or core dump files generated after opening a BLF file; application error logs referencing memory access violations or segmentation faults in the BLF parser.
  • Process: Unexpected termination of the Wireshark process (wireshark, tshark) immediately after opening a BLF file, particularly with exit codes indicating abnormal termination.

Mitigation and workarounds

Wireshark has released patched versions addressing this vulnerability: upgrade to 4.4.13 or later for the 4.4.x branch, or 4.6.3 or later for the 4.6.x branch. As a workaround prior to patching, users should avoid opening BLF files from untrusted sources and consider removing BLF file type associations with Wireshark. Organizations should implement user awareness training to discourage opening unsolicited capture files (Wireshark Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability received routine coverage from Linux distribution security channels, including SUSE, Fedora, and Debian package update announcements. Greenbone's January 2026 threat report noted the vulnerability among the month's disclosures. No significant researcher commentary or notable social media discussion beyond automated CVE tracking feeds has been observed for this moderate-severity issue.

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026
CVE-2026-15173MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesJul 08, 2026
CVE-2026-15172MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli-debuginfo
NoYesJul 08, 2026
CVE-2026-15171MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management