Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-5406
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-5406 is an uncontrolled recursion vulnerability in Wireshark's FC-SWILS (Fibre Channel Switch Fabric Internal Link Services) protocol dissector that allows denial of service via application crash. It affects Wireshark versions 4.4.0 through 4.4.14 and 4.6.0 through 4.6.4. The vulnerability was published on April 30, 2026, with patches released in the same timeframe. It carries a CVSS v3.1 base score of 5.5 (Medium), assigned by GitLab (GitHub Advisory, Wireshark Advisory).

Technical details

The root cause is classified as CWE-674 (Uncontrolled Recursion): the FC-SWILS dissector does not properly limit recursion depth when processing nested zone set objects, leading to a stack overflow and application crash. An attacker can trigger this by crafting a malicious PCAP file or network packet containing deeply nested FC-SWILS zone set structures, which causes Wireshark to recurse without bound when parsing the data. Exploitation requires local access and user interaction — specifically, a victim must open a malicious capture file or analyze crafted live traffic. The GitLab issue tracker entry (titled "FC-SWILS dissector stack overflow via nested zone set objects") documents the flaw (GitLab Issue, GitHub Advisory).

Impact

Successful exploitation causes Wireshark to crash, resulting in a denial of service for network analysts and security professionals relying on the tool for traffic analysis. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability of the Wireshark application itself. Because exploitation requires local access and user interaction, the blast radius is confined to individual analyst workstations rather than enabling lateral movement or remote system compromise (GitHub Advisory, Wireshark Advisory).

Exploitability

A GitLab issue report exists documenting the stack overflow behavior, but it does not contain functional exploit code — it is classified as an advisory rather than a working exploit (GitLab Issue). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (GitHub Advisory).

Exploitation steps

  1. Craft a malicious PCAP file: Create a packet capture file containing FC-SWILS protocol frames with deeply nested zone set objects designed to trigger unbounded recursion in Wireshark's dissector.
  2. Deliver the file to the target: Use social engineering, a shared network drive, email attachment, or other means to get a Wireshark user to open the crafted PCAP file on a system running a vulnerable version (4.4.0–4.4.14 or 4.6.0–4.6.4).
  3. Trigger the crash: When the victim opens the file in Wireshark, the FC-SWILS dissector processes the nested zone set objects, enters uncontrolled recursion, exhausts the stack, and crashes the application.
  4. Result: Wireshark crashes (denial of service); no code execution or data exfiltration is achieved (GitLab Issue, GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited PCAP files containing FC-SWILS protocol traffic delivered via email, file share, or download.
  • Logs: Wireshark crash reports or core dump files generated on analyst workstations; Windows Event Log entries or Linux crash logs showing abnormal Wireshark process termination.
  • Process: Wireshark process terminating unexpectedly (crash/segfault) immediately after opening a capture file containing FC-SWILS frames.

Mitigation and workarounds

Users should upgrade to Wireshark 4.6.5 or later (for the 4.6.x branch) or 4.4.15 or later (for the 4.4.x branch), which contain fixes for this vulnerability (Wireshark Advisory, Release Notes). As a temporary workaround prior to patching, avoid opening PCAP files from untrusted sources and refrain from analyzing network traffic from untrusted environments. Restricting Wireshark usage to trusted, controlled environments and limiting which users can open arbitrary capture files also reduces exposure.

Community reactions

Wireshark announced the fix via its official mailing lists (wireshark-announce and wireshark-users) in April and May 2026, and the security advisory was published at wnpa-sec-2026-10 (Wireshark Announce, Wireshark Advisory). Security news outlets including CyberSecurityNews and Cryptika covered the broader set of Wireshark vulnerabilities disclosed in this release cycle. Downstream Linux distributions including Debian and SUSE issued their own advisories and package updates incorporating the fix (Linux Security).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

wireshark

Affected

sid

wireshark: 4.6.5-1

Fixed

trixie

wireshark: 4.4.15-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

wireshark

Unknown

devel

wireshark

Unknown

focal (esm-apps)

wireshark

Unknown

jammy

wireshark

Unknown

jammy (esm-apps)

wireshark

Unknown

noble

wireshark

Unknown

noble (esm-apps)

wireshark

Unknown

resolute

wireshark

Unknown

RHEL / CentOS

Affected

RHEL 8

wireshark.src

Affected

RHEL 9

wireshark.src

Affected

RHEL 10

wireshark.src

Affected

SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76928HIGH7.5
  • Wireshark logoWireshark
  • wireshark
NoYesAug 19, 2026
CVE-2026-76927HIGH7.5
  • Wireshark logoWireshark
  • wireshark
NoYesAug 19, 2026
CVE-2026-76926MEDIUM6.5
  • Wireshark logoWireshark
  • wireshark-cli-debuginfo
NoYesAug 19, 2026
CVE-2026-76929MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 19, 2026
CVE-2026-76924MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management