CVE-2026-96423: 
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-96423 is a vulnerability described as a crash in the X11 protocol dissector within Wireshark. The CVE identifier is currently in Reserved status and full details have not yet been publicly published. Based on available Feedly intelligence, the vulnerability appears to affect Wireshark versions addressed in the 4.6.9 and 4.4.19 release cycles. No CVSS score has been assigned at this time (Feedly, Wireshark 4.6.9 Release Notes).

Technical details

The vulnerability resides in Wireshark's X11 protocol dissector, where a flaw causes the application to crash when processing certain network traffic. This class of issue is typically associated with improper input validation or out-of-bounds memory access (CWE-125 or CWE-476) during packet dissection. Because Wireshark can be configured to capture live traffic or open capture files, the attack surface includes both network-based and file-based vectors. Full technical details, including the precise root cause and any proof-of-concept code, have not been publicly disclosed as the CVE remains in Reserved status (Feedly, Wireshark 4.6.9 Release Notes).

Impact

Successful exploitation of this vulnerability would cause Wireshark to crash, resulting in a denial of service for the affected user or analyst. Since Wireshark operates as a network analysis tool rather than a network service, the primary impact is availability — an attacker could craft malicious X11 protocol traffic or a malicious capture file to repeatedly crash the application. There is no current evidence suggesting this vulnerability leads to remote code execution or data exfiltration (Feedly).

Exploitability

There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with CVE-2026-96423 at this time. The CVE remains in Reserved status, meaning exploitation details are not yet publicly available. No EPSS score has been assigned, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Mitigation and workarounds

Users should upgrade to Wireshark 4.6.9 or 4.4.19, which are the patched releases identified in Feedly intelligence as addressing this vulnerability. Until an upgrade is possible, analysts should avoid opening untrusted packet capture files and exercise caution when capturing live traffic from untrusted networks. Restricting Wireshark usage to trusted environments and capture files is a prudent interim measure (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes).

Community reactions

A brief mention of Wireshark 4.6.9 fixing 19 vulnerabilities (including this one) appeared on a cybersecurity news aggregator, but no significant vendor statements, notable researcher commentary, or broad community discussion specific to CVE-2026-96423 has been observed at this time (CyberUpdates365).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

wireshark

Affected

sid

wireshark

Affected

trixie

wireshark

Affected

Ubuntu

Unknown

bionic (esm-apps)

wireshark

Unknown

devel

wireshark

Unknown

focal (esm-apps)

wireshark

Unknown

jammy

wireshark

Unknown

jammy (esm-apps)

wireshark

Unknown

noble

wireshark

Unknown

noble (esm-apps)

wireshark

Unknown

resolute

wireshark

Unknown

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

wireshark.src

Affected

Source: This report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-96423MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark.src
NoNoSep 29, 2026
CVE-2026-96422MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoNoSep 29, 2026
CVE-2026-96421MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoNoSep 29, 2026
CVE-2026-96419MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoNoSep 29, 2026
CVE-2026-96420MEDIUM4.7
  • Wireshark logoWireshark
  • wireshark.src
NoNoSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management