CVE-2026-0961Out-of-bounds Write in Foundation Wireshark

Severity
6.5MEDIUMNVD
CNA5.5
EPSS
0.0%
top 93.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14

Description

BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDwireshark/wireshark4.4.04.4.13+1
CVEListV5wireshark_foundation/wireshark4.6.04.6.3+1
Debianwireshark/wireshark< 4.4.13-0+deb13u1+1

🔴Vulnerability Details

3
OSV
CVE-2026-0961: BLF file parser crash in Wireshark 42026-01-14
GHSA
GHSA-9pw2-p3rh-r9jh: BLF file parser crash in Wireshark 42026-01-14
CVEList
Out-of-bounds Write in Wireshark2026-01-14

📋Vendor Advisories

2
Red Hat
Wireshark: Wireshark: Denial of Service vulnerability in BLF file parser2026-01-14
Debian
CVE-2026-0961: wireshark - BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows den...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0961 — Out-of-bounds Write | cvebase