<Vulnerability name="CVE-2026-76880">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-19T22:44:05</PublicDate>
    <Bugzilla id="2520088" url="https://bugzilla.redhat.com/show_bug.cgi?id=2520088" xml:lang="en:us">
wireshark: Wireshark: Denial of Service via RRC protocol dissector out-of-bounds write
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-787</CWE>
    <Details xml:lang="en:us" source="Mitre">
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a specially crafted Universal Mobile Telecommunications System (UMTS) RRC protocol packet. The flaw resides in the UMTS RRC protocol dissector, which can lead to a crash of the Wireshark application. This can disrupt network analysis operations.
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact denial of service flaw in Wireshark's UMTS RRC protocol dissector can be triggered by processing a specially crafted packet. While exploitable by a remote attacker, successful exploitation requires a user to either open a malicious capture file or actively capture network traffic containing the crafted packet. This limits the attack surface to scenarios where Wireshark is actively used for network analysis.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this issue, avoid opening untrusted capture files or analyzing untrusted live network traffic with Wireshark. Users should only process network data from trusted sources to prevent potential denial of service attacks.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-76880
https://nvd.nist.gov/vuln/detail/CVE-2026-76880
https://gitlab.com/wireshark/wireshark/-/work_items/21478
https://www.wireshark.org/security/wnpa-sec-2026-88.html
    </References>
</Vulnerability>