
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3202 is a NULL Pointer Dereference vulnerability in the NTS-KE (Network Time Security Key Establishment) protocol dissector in Wireshark, allowing denial of service via application crash. It affects Wireshark versions 4.6.0 through 4.6.3, with version 4.6.4 being the first patched release. The vulnerability was disclosed on February 25, 2026, with the CVE assigned by GitLab Inc. CVSS v3.1 scores differ by source: NVD rates it 7.5 (High) while the CNA (GitLab Inc.) rates it 4.7 (Medium) (Wireshark Advisory, Red Hat).
The root cause is a NULL Pointer Dereference (CWE-476) in Wireshark's NTS-KE protocol dissector. When Wireshark processes specially crafted NTS-KE protocol packets — either from live network capture or a saved packet capture file — the dissector fails to properly validate a pointer before dereferencing it, causing the application to crash. According to the CNA's CVSS assessment, exploitation requires local access, high attack complexity, no privileges, and user interaction (i.e., the user must open or process the malicious packet), suggesting the primary attack vector is a crafted capture file rather than passive network sniffing (GitLab Issue, Wireshark Advisory).
Successful exploitation causes Wireshark to crash, resulting in a denial of service limited to the Wireshark application itself. There is no impact on data confidentiality or integrity — only availability of the Wireshark process is affected. The vulnerability does not enable code execution, privilege escalation, or lateral movement, and its scope is confined to the local user session running Wireshark (Red Hat, Wireshark Advisory).
.pcap or .pcapng) containing malformed NTS-KE protocol packets designed to trigger a NULL pointer dereference in Wireshark's NTS-KE dissector..pcap/.pcapng files containing NTS-KE protocol traffic delivered via email or file share.wireshark, tshark, or dumpcap) with a segmentation fault or access violation error referencing the NTS-KE dissector.Users should upgrade Wireshark to version 4.6.4 or later, which contains the fix for this vulnerability (Wireshark Advisory). As a temporary workaround prior to patching, users should avoid opening untrusted packet capture files and exercise caution when capturing live traffic from untrusted network sources. Linux distribution users (e.g., Fedora, Red Hat) should apply the updated packages provided through their respective package managers (Red Hat, Red Hat Bugzilla).
The Wireshark project announced the 4.6.4 release through its official mailing lists, noting fixes for multiple security vulnerabilities including this one (Wireshark Users List). Security news outlets including Linuxiac and CyberPress covered the 4.6.4 release, highlighting the security fixes (Linuxiac, CyberPress). Community reaction has been low-key given the limited severity and scope of the vulnerability, with no significant controversy or widespread concern noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."