CVE-2026-96420: 
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-96420 is a crash vulnerability in Wireshark's Toshiba file parser that can cause the application to crash when processing a malformed or crafted capture file. The flaw is tracked as Wireshark issue 21541 and was addressed in Wireshark version 4.6.9. The CVE status is currently listed as "Reserved," and the affected product is Wireshark by the Wireshark Foundation (Feedly, Wireshark Release Notes).

Technical details

The root cause of this vulnerability is a flaw in Wireshark's Toshiba file parser that fails to properly handle certain malformed input, leading to an application crash (likely a NULL pointer dereference or out-of-bounds read, consistent with CWE-125 or CWE-476). An attacker can exploit this by convincing a user to open a specially crafted Toshiba capture file within Wireshark, triggering the crash. Exploitation requires user interaction, as the victim must manually open the malicious file (Wireshark Release Notes, Feedly).

Impact

Successful exploitation results in a denial-of-service condition, causing Wireshark to crash and become unavailable. The primary impact is on availability; there is no evidence of code execution capability, and confidentiality and integrity impacts appear minimal. The vulnerability affects users who open untrusted Toshiba capture files with a vulnerable version of Wireshark (Wireshark Release Notes).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-96420. The CVE status remains "Reserved," and there is no indication of inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploitation requires user interaction (opening a malicious file), which limits the practical attack surface (Feedly).

Exploitation steps

  1. Craft malicious file: Create a specially crafted Toshiba capture file designed to trigger the parser flaw (issue 21541) in Wireshark's Toshiba file parser.
  2. Deliver the file: Distribute the malicious file to a target user via email attachment, file sharing, or social engineering, convincing them to open it in Wireshark.
  3. Trigger the crash: When the victim opens the file in a vulnerable version of Wireshark (prior to 4.6.9), the Toshiba file parser encounters the malformed input and crashes the application.
  4. Result: Wireshark crashes, causing a denial-of-service for the user's analysis session (Wireshark Release Notes).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .toshiba or similarly named capture files received from untrusted sources.
  • Logs: Wireshark crash reports or application error logs referencing the Toshiba file parser or issue 21541.
  • Process: Unexpected termination of the Wireshark process (wireshark.exe or wireshark) shortly after opening a capture file.

Mitigation and workarounds

Users should upgrade to Wireshark version 4.6.9 or later, which contains the fix for this vulnerability (issue 21541) (Wireshark Release Notes). As a workaround, users should avoid opening Toshiba capture files from untrusted or unknown sources until the patch is applied. No additional configuration-based workarounds have been published.

Community reactions

The vulnerability was noted in the Wireshark 4.6.9 release announcement and covered by security news aggregators as part of a broader release fixing 19 vulnerabilities (cyberupdates365, Wireshark Announce). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

wireshark

Affected

sid

wireshark

Affected

trixie

wireshark

Affected

Ubuntu

Unknown

bionic (esm-apps)

wireshark

Unknown

devel

wireshark

Unknown

focal (esm-apps)

wireshark

Unknown

jammy

wireshark

Unknown

jammy (esm-apps)

wireshark

Unknown

noble

wireshark

Unknown

noble (esm-apps)

wireshark

Unknown

resolute

wireshark

Unknown

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

wireshark.src

Affected

Source: This report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NoNoSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoNoSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoNoSep 29, 2026
CVE-2026-96419MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoNoSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NoNoSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management