CVE-2026-0962
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-0962 is an Out-of-bounds Write (CWE-787) vulnerability in the SOME/IP-SD protocol dissector of Wireshark that allows denial of service via a dissector crash. It affects Wireshark versions 4.6.0 through 4.6.2 and 4.4.0 through 4.4.12 (NVD CPE data also indicates 4.2.2 through 4.4.12 as vulnerable). The CVE was published on January 14, 2026, and assigned by GitLab Inc. It carries a CVSS v3.1 base score of 6.5 (Medium) per NVD, and 5.3 (Medium) per the CNA (GitLab) (Wireshark Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in Wireshark's SOME/IP-SD (Service Discovery) protocol dissector. An attacker can trigger the crash by sending specially crafted malformed SOME/IP-SD protocol packets over the network, or by inducing a victim to open a malicious packet capture file containing such packets — requiring user interaction. The out-of-bounds write condition causes the dissector to crash, resulting in denial of service. A proof-of-concept issue has been filed in the Wireshark GitLab repository (GitLab Issue, Wireshark Advisory).

Impact

Successful exploitation results in a crash of the Wireshark application, causing a denial of service with high availability impact. There is no impact to confidentiality or integrity of data — the vulnerability cannot be used to read or modify sensitive information or execute arbitrary code. The scope is limited to the Wireshark process itself; lateral movement or data exfiltration are not associated with this vulnerability (Wireshark Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Reconnaissance: Identify environments where Wireshark 4.4.0–4.4.12 or 4.6.0–4.6.2 is deployed and used to analyze live network traffic or packet capture files, particularly in automotive or embedded systems contexts where SOME/IP-SD is common.
  2. Craft malformed SOME/IP-SD packets: Construct a specially crafted SOME/IP-SD protocol packet or packet capture (.pcap/.pcapng) file containing malformed data designed to trigger the out-of-bounds write in the dissector.
  3. Deliver the payload: Either (a) transmit the malformed SOME/IP-SD packets over a network segment being monitored by a vulnerable Wireshark instance, or (b) socially engineer a target user into opening the malicious capture file in Wireshark.
  4. Trigger the crash: When Wireshark processes the malformed SOME/IP-SD data, the out-of-bounds write condition is triggered, causing the dissector and application to crash, resulting in denial of service (GitLab Issue, Wireshark Advisory).

Indicators of compromise

  • Network: Unusual or malformed SOME/IP-SD packets (UDP port 30490 by default) on monitored network segments, particularly with anomalous payload lengths or malformed service discovery entries.
  • Logs: Wireshark crash reports or core dump files generated around the time of processing SOME/IP-SD traffic; application crash logs referencing the SOME/IP-SD dissector.
  • File System: Unexpected or unsolicited .pcap/.pcapng files delivered via email, file share, or download containing SOME/IP-SD traffic; Wireshark crash dump files (e.g., wireshark_crash_*.dmp on Windows or core dumps on Linux).
  • Process: Wireshark process terminating unexpectedly or with a segmentation fault/access violation when processing specific network traffic or opening specific capture files (GitLab Issue).

Mitigation and workarounds

Upgrade Wireshark to version 4.4.13 or later (for the 4.4.x branch) or 4.6.3 or later (for the 4.6.x branch) to remediate the vulnerability. As a temporary workaround, restrict analysis of untrusted SOME/IP-SD protocol traffic, implement network segmentation to limit exposure to potentially malicious SOME/IP-SD packets, and avoid opening suspicious or untrusted packet capture files in Wireshark until patching is complete (Wireshark Advisory, Red Hat Bugzilla).

Community reactions

Red Hat tracked the vulnerability via their security response process and assigned it medium severity, with a corresponding Bugzilla entry filed on January 14, 2026. Linux distribution maintainers including SUSE, Fedora, and Debian issued package updates addressing this and related Wireshark vulnerabilities. Coverage was noted in German Linux security outlet pro-linux.de and Linux compatibility news aggregators, reflecting routine community attention to Wireshark security updates (Red Hat Bugzilla, Wireshark Advisory).

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026
CVE-2026-15173MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesJul 08, 2026
CVE-2026-15172MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli-debuginfo
NoYesJul 08, 2026
CVE-2026-15171MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management