CVE-2026-5408
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-5408 is an uncontrolled recursion vulnerability in Wireshark's BT-DHT (Bluetooth Distributed Hash Table) protocol dissector that allows a local attacker to cause a denial of service by crashing the application. It affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The vulnerability was published on April 30, 2026, with patches released shortly after. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Wireshark Advisory).

Technical details

The root cause is CWE-674 (Uncontrolled Recursion): the BT-DHT dissector fails to properly limit recursive function calls when processing malformed or specially crafted packet data containing deeply nested structures. An attacker can trigger a stack overflow by supplying a packet capture file with nested structs that cause the dissector to recurse without bound, ultimately exhausting the call stack. Exploitation requires user interaction — specifically, a victim must open a malicious capture file in Wireshark. The vulnerability is tracked in the Wireshark issue tracker as a "BT-DHT dissector stack overflow via nested structs" (GitLab Issue, GitHub Advisory).

Impact

Successful exploitation results in a crash of the Wireshark application, causing a denial of service that disrupts packet analysis capabilities. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability of the Wireshark process itself. The scope is unchanged, meaning the crash is contained to the Wireshark application and does not affect the underlying operating system or other processes (GitHub Advisory, Wireshark Advisory).

Exploitability

No confirmed in-the-wild exploitation has been reported. The Feedly executive summary notes that while GitLab issue tracker pages referencing the vulnerability exist, no functional exploit code or reproduction steps are publicly available — the referenced pages contain only metadata and bug report descriptions (GitLab Issue). The EPSS score is approximately 0.013–0.016%, placing it in the low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Multiple Nessus detection plugins (IDs 311426, 311427, 311436, 311437, 313009, 318251) are available for scanning (GitHub Advisory).

Exploitation steps

  1. Craft a malicious capture file: Create a .pcap or .pcapng file containing BT-DHT protocol packets with deeply nested struct payloads designed to trigger unbounded recursion in Wireshark's BT-DHT dissector.
  2. Deliver the file to the target: Use social engineering, email, file sharing, or other means to get the victim to download or receive the malicious capture file, since exploitation requires local user interaction.
  3. Trigger the vulnerability: Convince the victim to open the malicious capture file in a vulnerable version of Wireshark (4.4.0–4.4.14 or 4.6.0–4.6.4). Wireshark will automatically invoke the BT-DHT dissector on the relevant packets.
  4. Achieve denial of service: The BT-DHT dissector recursively processes the nested structures without bound, causing a stack overflow that crashes the Wireshark process (GitLab Issue, GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .pcap/.pcapng files received via email, messaging, or file transfer containing BT-DHT protocol traffic with anomalously deep nesting.
  • Process: Wireshark process terminating unexpectedly or with a crash/segmentation fault signal shortly after opening a capture file; crash dump files generated in the Wireshark working directory or OS crash reporting folder.
  • Logs: OS-level application crash logs (e.g., Windows Event Log Application errors for Wireshark.exe, or Linux dmesg/journalctl entries) referencing stack overflow or segmentation fault in the Wireshark process.

Mitigation and workarounds

Wireshark has released patched versions addressing this vulnerability: upgrade to 4.6.5 or later (for the 4.6.x branch) or 4.4.15 or later (for the 4.4.x branch) (Wireshark Advisory, Release Notes). As a workaround prior to patching, restrict users from opening packet capture files from untrusted or unknown sources, and consider implementing file-type controls or user awareness training. Linux distribution packages (Debian, SUSE, and others) have also issued updated packages incorporating the fix.

Community reactions

The Wireshark Foundation issued a formal security advisory (wnpa-sec-2026-09) and announced the fix via the wireshark-announce mailing list (Wireshark Announce). Security news outlets including CyberSecurityNews and Cryptika covered the broader set of Wireshark vulnerabilities disclosed in this release cycle, though coverage was not exclusively focused on CVE-2026-5408 (CyberSecurityNews). Community reaction has been routine, consistent with a moderate-severity DoS vulnerability in a widely used analysis tool with a straightforward patch available.

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76928HIGH7.5
  • Wireshark logoWireshark
  • wireshark-devel
NoYesAug 19, 2026
CVE-2026-76924MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesAug 19, 2026
CVE-2026-76929MEDIUM4.7
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 19, 2026
CVE-2026-76927MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark
NoYesAug 19, 2026
CVE-2026-76926LOW3.1
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management