
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-96422 is a vulnerability in Wireshark's Frame protocol metadissector that can cause a crash when parsing Frame protocol data. The CVE is currently in "Reserved" status, and the affected product is Wireshark. Based on available Feedly threat intelligence, fixed versions appear to include Wireshark 4.6.9 and 4.4.19, released in September 2026. No CVSS score has been publicly assigned at this time (Feedly, Wireshark 4.6.9 Release Notes).
The vulnerability resides in Wireshark's Frame protocol metadissector, which is responsible for parsing Frame protocol metadata during packet capture analysis. A malformed or specially crafted packet capture file could trigger the crash condition when the dissector processes Frame protocol data. The root cause is likely an improper input validation or unhandled edge case in the dissector logic (CWE-20 or CWE-125), though the full technical details have not been publicly disclosed given the CVE's reserved status (Feedly, Wireshark 4.6.9 Release Notes).
Successful exploitation of this vulnerability results in a crash of the Wireshark application, causing a denial of service to the analyst or user processing the affected packet capture. Since Wireshark typically runs with user-level privileges, the impact is generally limited to availability of the application rather than system-wide compromise. There is no current evidence of code execution capability, data exfiltration risk, or lateral movement potential associated with this vulnerability (Feedly).
There are no known public proof-of-concept exploits, exploit kits, or evidence of in-the-wild exploitation for CVE-2026-96422 at this time. The CVE remains in "Reserved" status, and no EPSS score or CISA KEV catalog listing has been identified. Exploitation would require an attacker to convince a Wireshark user to open a maliciously crafted packet capture file, limiting the practical attack surface (Feedly).
.pcap or .pcapng) containing malformed Frame protocol metadata designed to trigger the crash condition in Wireshark's metadissector..pcap or .pcapng files received via email or downloaded from untrusted sources.wireshark, tshark) without user-initiated closure.Users should upgrade to Wireshark 4.6.9 or 4.4.19, which appear to contain fixes for this vulnerability based on their September 2026 release timing. As a workaround, users should avoid opening packet capture files from untrusted or unknown sources. Organizations should ensure Wireshark installations are kept up to date via their standard patch management processes (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes).
Coverage of CVE-2026-96422 has been limited, consistent with its status as one of multiple vulnerabilities addressed in the Wireshark 4.6.9 release. A security news outlet noted that Wireshark 4.6.9 fixes 19 vulnerabilities in total, suggesting this CVE is part of a broader patch batch rather than a standalone critical issue (CyberUpdates365).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
wireshark
devel
wireshark
focal (esm-apps)
wireshark
jammy
wireshark
jammy (esm-apps)
wireshark
noble
wireshark
noble (esm-apps)
wireshark
resolute
wireshark
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."