<Vulnerability name="CVE-2026-76891">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-08-19T22:46:40</PublicDate>
    <Bugzilla id="2520092" url="https://bugzilla.redhat.com/show_bug.cgi?id=2520092" xml:lang="en:us">
wireshark: Wireshark: Denial of Service via sharkd crash
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.1</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-248</CWE>
    <Details xml:lang="en:us" source="Mitre">
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the sharkd component of Wireshark. A remote attacker could exploit this vulnerability, which requires user interaction and has high attack complexity, by triggering a crash. This issue leads to a denial of service (DoS), making the sharkd component unavailable.
    </Details>
    <Statement xml:lang="en:us">
Red Hat Enterprise Linux 6 through 9 ship Wireshark versions 1.x through 3.x, which predate the introduction of the vulnerable sharkd code in version 4.4.0 and are therefore not affected by this flaw. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship Wireshark 4.4.2, which is within the affected range (4.4.0–4.4.17).
    </Statement>
    <Mitigation xml:lang="en:us">
Avoid using sharkd to process untrusted capture files or to analyze traffic from untrusted network segments.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>wireshark</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-76891
https://nvd.nist.gov/vuln/detail/CVE-2026-76891
https://gitlab.com/wireshark/wireshark/-/work_items/21395
https://www.wireshark.org/security/wnpa-sec-2026-64.html
    </References>
</Vulnerability>