
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-96420 is a crash vulnerability in Wireshark's Toshiba file parser that can cause the application to crash when processing a malformed or crafted capture file. The flaw is tracked as Wireshark issue 21541 and was addressed in Wireshark version 4.6.9. The CVE status is currently listed as "Reserved," and the affected product is Wireshark by the Wireshark Foundation (Feedly, Wireshark Release Notes).
The root cause of this vulnerability is a flaw in Wireshark's Toshiba file parser that fails to properly handle certain malformed input, leading to an application crash (likely a NULL pointer dereference or out-of-bounds read, consistent with CWE-125 or CWE-476). An attacker can exploit this by convincing a user to open a specially crafted Toshiba capture file within Wireshark, triggering the crash. Exploitation requires user interaction, as the victim must manually open the malicious file (Wireshark Release Notes, Feedly).
Successful exploitation results in a denial-of-service condition, causing Wireshark to crash and become unavailable. The primary impact is on availability; there is no evidence of code execution capability, and confidentiality and integrity impacts appear minimal. The vulnerability affects users who open untrusted Toshiba capture files with a vulnerable version of Wireshark (Wireshark Release Notes).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-96420. The CVE status remains "Reserved," and there is no indication of inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploitation requires user interaction (opening a malicious file), which limits the practical attack surface (Feedly).
.toshiba or similarly named capture files received from untrusted sources.wireshark.exe or wireshark) shortly after opening a capture file.Users should upgrade to Wireshark version 4.6.9 or later, which contains the fix for this vulnerability (issue 21541) (Wireshark Release Notes). As a workaround, users should avoid opening Toshiba capture files from untrusted or unknown sources until the patch is applied. No additional configuration-based workarounds have been published.
The vulnerability was noted in the Wireshark 4.6.9 release announcement and covered by security news aggregators as part of a broader release fixing 19 vulnerabilities (cyberupdates365, Wireshark Announce). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
wireshark
devel
wireshark
focal (esm-apps)
wireshark
jammy
wireshark
jammy (esm-apps)
wireshark
noble
wireshark
noble (esm-apps)
wireshark
resolute
wireshark
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."