CVE-2026-3202
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-3202 is a NULL Pointer Dereference vulnerability in the NTS-KE (Network Time Security Key Establishment) protocol dissector in Wireshark, allowing denial of service via application crash. It affects Wireshark versions 4.6.0 through 4.6.3, with version 4.6.4 being the first patched release. The vulnerability was disclosed on February 25, 2026, with the CVE assigned by GitLab Inc. CVSS v3.1 scores differ by source: NVD rates it 7.5 (High) while the CNA (GitLab Inc.) rates it 4.7 (Medium) (Wireshark Advisory, Red Hat).

Technical details

The root cause is a NULL Pointer Dereference (CWE-476) in Wireshark's NTS-KE protocol dissector. When Wireshark processes specially crafted NTS-KE protocol packets — either from live network capture or a saved packet capture file — the dissector fails to properly validate a pointer before dereferencing it, causing the application to crash. According to the CNA's CVSS assessment, exploitation requires local access, high attack complexity, no privileges, and user interaction (i.e., the user must open or process the malicious packet), suggesting the primary attack vector is a crafted capture file rather than passive network sniffing (GitLab Issue, Wireshark Advisory).

Impact

Successful exploitation causes Wireshark to crash, resulting in a denial of service limited to the Wireshark application itself. There is no impact on data confidentiality or integrity — only availability of the Wireshark process is affected. The vulnerability does not enable code execution, privilege escalation, or lateral movement, and its scope is confined to the local user session running Wireshark (Red Hat, Wireshark Advisory).

Exploitation steps

  1. Craft malicious capture file: Create a specially crafted packet capture file (e.g., .pcap or .pcapng) containing malformed NTS-KE protocol packets designed to trigger a NULL pointer dereference in Wireshark's NTS-KE dissector.
  2. Deliver to target: Distribute the malicious capture file to a target user via email attachment, file share, or other social engineering means, or position the attacker on a network segment where the target is capturing live traffic containing crafted NTS-KE packets.
  3. Trigger crash: Induce the target user to open the malicious capture file in Wireshark 4.6.0–4.6.3, or have Wireshark capture live traffic containing the crafted packets. The NTS-KE dissector processes the malformed data and dereferences a NULL pointer.
  4. Denial of service achieved: Wireshark crashes, disrupting any ongoing packet analysis or capture session (Wireshark Advisory, GitLab Issue).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .pcap/.pcapng files containing NTS-KE protocol traffic delivered via email or file share.
  • Logs: Wireshark crash reports or core dump files generated in the user's home directory or system crash log directory following processing of NTS-KE packets.
  • Process: Unexpected termination of the Wireshark process (wireshark, tshark, or dumpcap) with a segmentation fault or access violation error referencing the NTS-KE dissector.

Mitigation and workarounds

Users should upgrade Wireshark to version 4.6.4 or later, which contains the fix for this vulnerability (Wireshark Advisory). As a temporary workaround prior to patching, users should avoid opening untrusted packet capture files and exercise caution when capturing live traffic from untrusted network sources. Linux distribution users (e.g., Fedora, Red Hat) should apply the updated packages provided through their respective package managers (Red Hat, Red Hat Bugzilla).

Community reactions

The Wireshark project announced the 4.6.4 release through its official mailing lists, noting fixes for multiple security vulnerabilities including this one (Wireshark Users List). Security news outlets including Linuxiac and CyberPress covered the 4.6.4 release, highlighting the security fixes (Linuxiac, CyberPress). Community reaction has been low-key given the limited severity and scope of the vulnerability, with no significant controversy or widespread concern noted.

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026
CVE-2026-15173MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesJul 08, 2026
CVE-2026-15172MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli-debuginfo
NoYesJul 08, 2026
CVE-2026-15171MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management