
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0962 is an Out-of-bounds Write (CWE-787) vulnerability in the SOME/IP-SD protocol dissector of Wireshark that allows denial of service via a dissector crash. It affects Wireshark versions 4.6.0 through 4.6.2 and 4.4.0 through 4.4.12 (NVD CPE data also indicates 4.2.2 through 4.4.12 as vulnerable). The CVE was published on January 14, 2026, and assigned by GitLab Inc. It carries a CVSS v3.1 base score of 6.5 (Medium) per NVD, and 5.3 (Medium) per the CNA (GitLab) (Wireshark Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in Wireshark's SOME/IP-SD (Service Discovery) protocol dissector. An attacker can trigger the crash by sending specially crafted malformed SOME/IP-SD protocol packets over the network, or by inducing a victim to open a malicious packet capture file containing such packets — requiring user interaction. The out-of-bounds write condition causes the dissector to crash, resulting in denial of service. A proof-of-concept issue has been filed in the Wireshark GitLab repository (GitLab Issue, Wireshark Advisory).
Successful exploitation results in a crash of the Wireshark application, causing a denial of service with high availability impact. There is no impact to confidentiality or integrity of data — the vulnerability cannot be used to read or modify sensitive information or execute arbitrary code. The scope is limited to the Wireshark process itself; lateral movement or data exfiltration are not associated with this vulnerability (Wireshark Advisory, Red Hat Bugzilla).
.pcap/.pcapng) file containing malformed data designed to trigger the out-of-bounds write in the dissector..pcap/.pcapng files delivered via email, file share, or download containing SOME/IP-SD traffic; Wireshark crash dump files (e.g., wireshark_crash_*.dmp on Windows or core dumps on Linux).Upgrade Wireshark to version 4.4.13 or later (for the 4.4.x branch) or 4.6.3 or later (for the 4.6.x branch) to remediate the vulnerability. As a temporary workaround, restrict analysis of untrusted SOME/IP-SD protocol traffic, implement network segmentation to limit exposure to potentially malicious SOME/IP-SD packets, and avoid opening suspicious or untrusted packet capture files in Wireshark until patching is complete (Wireshark Advisory, Red Hat Bugzilla).
Red Hat tracked the vulnerability via their security response process and assigned it medium severity, with a corresponding Bugzilla entry filed on January 14, 2026. Linux distribution maintainers including SUSE, Fedora, and Debian issued package updates addressing this and related Wireshark vulnerabilities. Coverage was noted in German Linux security outlet pro-linux.de and Linux compatibility news aggregators, reflecting routine community attention to Wireshark security updates (Red Hat Bugzilla, Wireshark Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."