CVE-2026-5299
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-5299 is a denial-of-service vulnerability caused by uncontrolled recursion in Wireshark's ICMPv6 PvD (Prefix Validation Data) protocol dissector. It affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The vulnerability was published on April 30, 2026, and assigned by GitLab. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Wireshark Advisory).

Technical details

The root cause is CWE-674 (Uncontrolled Recursion): the ICMPv6 PvD dissector fails to properly limit the depth of recursive processing when parsing malformed ICMPv6 packets, leading to excessive resource consumption and an application crash. Exploitation requires a local attack vector with user interaction — specifically, a user must open or analyze a crafted packet capture file containing malicious ICMPv6 PvD packets. The vulnerability is tracked in the Wireshark issue tracker as issue #21077 (Wireshark Issue, GitHub Advisory).

Impact

Successful exploitation results in a crash of the Wireshark application, causing a denial-of-service condition that renders packet analysis capabilities unavailable. There is no impact on confidentiality or data integrity — only availability is affected. Users may also lose unsaved analysis work at the time of the crash (GitHub Advisory, Wireshark Advisory).

Exploitability

A proof-of-concept reference exists in the form of the Wireshark GitLab issue (#21077), though it does not contain weaponized exploit code (Wireshark Issue). There is no evidence of active in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating a very low probability of exploitation in the near term (GitHub Advisory).

Exploitation steps

  1. Craft malicious capture file: Create a pcap/pcapng file containing malformed ICMPv6 packets with a specially structured PvD (Prefix Validation Data) option designed to trigger exponential recursion in Wireshark's dissector.
  2. Deliver the file: Distribute the crafted capture file to a target user via email, file share, or other means, or position it on a network segment where automated Wireshark-based analysis tools will process it.
  3. Trigger dissection: Induce the target user (or automated process) to open the malicious capture file in an affected version of Wireshark (4.4.0–4.4.14 or 4.6.0–4.6.4).
  4. Achieve denial of service: Wireshark's ICMPv6 PvD dissector enters uncontrolled recursion while parsing the malformed packet, exhausting stack or memory resources and crashing the application (Wireshark Issue, GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .pcap or .pcapng files received from external sources, particularly those containing ICMPv6 traffic.
  • Process: Wireshark process terminating unexpectedly or generating crash dumps/core files after opening a specific capture file.
  • Logs: Application crash reports or stack overflow errors in Wireshark logs or OS crash reporting tools (e.g., Windows Error Reporting, macOS crash reporter, Linux core dumps) referencing ICMPv6 or PvD dissector functions.

Mitigation and workarounds

Users should upgrade to Wireshark version 4.6.5 or later (for the 4.6.x branch) or version 4.4.15 or later (for the 4.4.x branch) to remediate this vulnerability (Wireshark Advisory, Release Notes). As a temporary workaround prior to patching, avoid opening untrusted or externally sourced pcap files in affected Wireshark versions, and restrict Wireshark usage to trusted capture sources only. Nessus detection plugins (IDs 311593, 313009, 313625) are available to identify vulnerable installations (Tenable).

Community reactions

The Wireshark project published a security advisory (wnpa-sec-2026-12) and release announcements via their mailing lists upon disclosure (Wireshark Announce). Security news outlets including CyberSecurityNews and Cryptika covered the broader set of Wireshark vulnerabilities disclosed alongside CVE-2026-5299, with some headlines emphasizing code execution risks from the broader release (CyberSecurityNews). Linux distribution security teams, including Debian, issued advisories and package updates addressing this and related Wireshark vulnerabilities (LinuxSecurity).

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76928HIGH7.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 19, 2026
CVE-2026-76924MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NoYesAug 19, 2026
CVE-2026-76929MEDIUM4.7
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 19, 2026
CVE-2026-76927MEDIUM4.7
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 19, 2026
CVE-2026-76926LOW3.1
  • Wireshark logoWireshark
  • wireshark
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management