CVE-2026-3203
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-3203 is a buffer over-read vulnerability in the RF4CE Profile protocol dissector in Wireshark that allows denial of service. It affects Wireshark versions 4.6.0 through 4.6.3 and 4.4.0 through 4.4.13. The vulnerability was disclosed on February 25, 2026, with patches released in versions 4.6.4 and 4.4.14. The CNA (GitLab Inc.) assigned a CVSS v3.1 base score of 5.5 (Medium), while NVD assessed it at 7.5 (High) (Wireshark Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-126 (Buffer Over-read) and resides in Wireshark's RF4CE Profile protocol dissector. When Wireshark processes malformed RF4CE packets — either from a live network capture or a crafted pcap file — the dissector reads beyond the bounds of an allocated buffer, triggering an application crash. The NVD vector (AV:N/AC:L/PR:N/UI:N) indicates network-based exploitation with no authentication or user interaction required, while the CNA vector (AV:L/AC:L/PR:N/UI:R) reflects a local file-based attack scenario where a user opens a malicious pcap file. The issue is tracked in the Wireshark GitLab issue tracker (GitLab Issue, Red Hat Bugzilla).

Impact

Successful exploitation causes Wireshark to crash, resulting in a denial of service that disrupts network packet analysis and security monitoring activities. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot use this vulnerability to access sensitive data or modify system state. Organizations relying on Wireshark for real-time traffic analysis or forensic investigation of pcap files may experience interruption to those workflows (Wireshark Advisory, Red Hat CVE).

Exploitation steps

  1. Craft a malformed pcap file: Create a pcap file containing specially crafted RF4CE Profile protocol packets with malformed fields designed to trigger a buffer over-read in Wireshark's dissector.
  2. Deliver the file to the target: Send the malicious pcap file to a Wireshark user via email, file share, or other means, or position the attacker on a network segment where Wireshark is performing live capture of RF4CE traffic.
  3. Trigger the crash: When the target user opens the malicious pcap file in a vulnerable version of Wireshark (4.6.0–4.6.3 or 4.4.0–4.4.13), or when Wireshark captures and dissects the malformed RF4CE packets live, the RF4CE Profile dissector performs an out-of-bounds read, causing the application to crash.
  4. Achieve denial of service: The Wireshark process terminates, disrupting any ongoing packet analysis or monitoring session (GitLab Issue, Wireshark Advisory).

Indicators of compromise

  • Process: Unexpected termination (crash) of the Wireshark process (wireshark, tshark, or dumpcap) without user-initiated exit, particularly when processing RF4CE-related traffic or pcap files.
  • Logs: Operating system crash/fault logs (e.g., Windows Event Log application errors, Linux core dumps) referencing the Wireshark binary around the time of processing RF4CE packets.
  • File System: Presence of unexpected or externally sourced pcap files containing RF4CE protocol data delivered to analyst workstations.
  • Network: Unusual RF4CE protocol traffic on monitored network segments, particularly packets with malformed or oversized fields in the RF4CE Profile layer.

Mitigation and workarounds

Upgrade Wireshark to version 4.6.4 or later (for the 4.6.x branch) or version 4.4.14 or later (for the 4.4.x branch) to remediate this vulnerability. As a temporary workaround, avoid opening pcap files from untrusted sources and restrict live capture to trusted network segments. Red Hat Enterprise Linux 10 users can apply the fix via errata RHSA-2026:9666 (Wireshark Advisory, Red Hat Errata, Red Hat Bugzilla).

Community reactions

Coverage of this vulnerability has been primarily limited to Linux distribution security update announcements (Debian, Fedora, AlmaLinux, SUSE) and security news outlets such as Linuxiac and CyberPress, which noted the release of Wireshark 4.6.4 and 4.4.14 with patches for multiple security issues. The Wireshark mailing lists (wireshark-announce and wireshark-users) carried the official release notifications. No significant independent researcher commentary or social media discussion has been observed beyond routine vulnerability aggregation (Linuxiac, CyberPress).

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026
CVE-2026-15173MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesJul 08, 2026
CVE-2026-15172MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli-debuginfo
NoYesJul 08, 2026
CVE-2026-15171MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management