CVE-2026-0959
published 2026-01-14CVE-2026-0959: IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.18%
7.5th percentile
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.6.3-1 (forky) | wireshark 4.6.3-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.3-1 | 4.6.3-1 |
| wireshark | wireshark | >= 4.4.0 < 4.4.13 | 4.4.13 |
| wireshark | wireshark | >= 4.6.0 < 4.6.3 | 4.6.3 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.13 | 4.4.13 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.3 | 4.6.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Out-of-bounds Write in Wireshark
vendor_gitlab·2026-01-14·CVSS 6.5
CVE-2026-0959 [MEDIUM] CWE-787 Out-of-bounds Write in Wireshark
Out-of-bounds Write in Wireshark
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.13 (affected)
Solution: Upgrade to version 4.6.3 or above
Credit: OSS-Fuzz
Red Hat
Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash
vendor_redhat·2026-01-14·CVSS 5.3
CVE-2026-0959 [MEDIUM] CWE-787 Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash
Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit a crash in the IEEE 802.11 protocol dissector by crafting a malicious network packet. This vulnerability leads to a denial of service, making the Wireshark application unavailable.
Statement: This vulnerability is rated Moderate for Red Hat. An out-of-bounds write flaw in the IEEE 802.11 protocol dissector of Wireshark can lead to a denial of service. Exploitation requires user interaction, as a malicious packet capture file must be opened, and has high attack complexity, limiting the overall impact.
Mitigation: To mitigate this issue,
Debian
CVE-2026-0959: wireshark - IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4....
vendor_debian·2026·CVSS 5.3
CVE-2026-0959 [MEDIUM] CVE-2026-0959: wireshark - IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4....
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
GHSA
GHSA-fp4m-fp9q-cxfx: IEEE 802
ghsa_unreviewed·2026-01-14
CVE-2026-0959 [MEDIUM] CWE-787 GHSA-fp4m-fp9q-cxfx: IEEE 802
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
OSV
CVE-2026-0959: IEEE 802
osv·2026-01-14·CVSS 6.5
CVE-2026-0959 [MEDIUM] CVE-2026-0959: IEEE 802
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-0959 [MEDIUM] CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0959 :
Wireshark vulnerability analysis and mitigation
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
wireshark-gnome
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homebrew Severity MEDIUM
Bugzilla
CVE-2026-0959 Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash
bugzilla·2026-01-14·CVSS 6.5
CVE-2026-0959 [MEDIUM] CVE-2026-0959 Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash
CVE-2026-0959 Wireshark: Wireshark: Denial of service via IEEE 802.11 protocol dissector crash
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
2026-01-14
Published