CVE-2026-3202
published 2026-02-25CVE-2026-3202: NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
PriorityP433high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.16%
5.3th percentile
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 4.6.4-1 (forky) | wireshark 4.6.4-1 (forky) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 4.6.4-1 | 4.6.4-1 |
| wireshark | wireshark | >= 4.6.0 < 4.6.4 | 4.6.4 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.4 | 4.6.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: NULL Pointer Dereference in Wireshark
vendor_redhat·2026-02-25·CVSS 4.7
CVE-2026-3202 [MEDIUM] CWE-476 wireshark: NULL Pointer Dereference in Wireshark
wireshark: NULL Pointer Dereference in Wireshark
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
A flaw was found in the NTS-KE dissector in Wireshark. This issue occurs when malformed packets are decoded from a pcap file or the network, causing a NULL pointer dereference, resulting in a denial of service.
Statement: This issue will cause a crash in Wireshark with no other security impact. Also, this flaw can only be exploited when a malformed pcap file is processed. Due to these reasons, this vulnerability has been rated with a moderate severity.
Mitigation: If the NTS-KE protocol dissector is not being used, it can be disabled via the "Enabled Protocols" dialog box in the Wireshark GUI application. This will also disable the protocol dissector whe
GitLab
NULL Pointer Dereference in Wireshark
vendor_gitlab·2026-02-25·CVSS 7.5
CVE-2026-3202 [HIGH] CWE-476 NULL Pointer Dereference in Wireshark
NULL Pointer Dereference in Wireshark
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, <4.6.4 (affected)
Solution: Upgrade to version 4.6.4 or above
Debian
CVE-2026-3202: wireshark - NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of ser...
vendor_debian·2026·CVSS 4.7
CVE-2026-3202 [MEDIUM] CVE-2026-3202: wireshark - NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of ser...
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 4.6.4-1)
sid: resolved (fixed in 4.6.4-1)
trixie: resolved
OSV
CVE-2026-3202: NTS-KE protocol dissector crash in Wireshark 4
osv·2026-02-25·CVSS 7.5
CVE-2026-3202 [HIGH] CVE-2026-3202: NTS-KE protocol dissector crash in Wireshark 4
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
GHSA
GHSA-g4x4-mr34-3pw3: NTS-KE protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-02-25
CVE-2026-3202 [MEDIUM] CWE-476 GHSA-g4x4-mr34-3pw3: NTS-KE protocol dissector crash in Wireshark 4
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0961 [MEDIUM] CVE-2026-0961 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0961 :
Wireshark vulnerability analysis and mitigation
BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-driver-storage-disk
libvirt-daemon-driver-storage-iscsi
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homeb
Wiz
CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-0959 [MEDIUM] CVE-2026-0959 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0959 :
Wireshark vulnerability analysis and mitigation
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
wireshark-gnome
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Homebrew Severity MEDIUM
Wiz
CVE-2026-3201 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3201 [MEDIUM] CVE-2026-3201 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3201 :
Wireshark vulnerability analysis and mitigation
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-client-qemu
libvirt-daemon-config-network
Sources
Alpine 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Ec
Wiz
CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.7
CVE-2026-0960 [MEDIUM] CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0960 :
Wireshark vulnerability analysis and mitigation
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Source : NVD
## 5.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-libs
libwireshark19
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Debian 12 Severity MEDIUM No Fix Added at: Jan
Wiz
CVE-2026-3202 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3202 [MEDIUM] CVE-2026-3202 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3202 :
Wireshark vulnerability analysis and mitigation
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-driver-interface
libvirt-daemon-driver-storage-rbd
Sources
Alpine 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Homebrew Severity HIGH Has Fix Added at: Mar 03, 2026
Red Hat 6, 7 Severity MEDIUM No Fix Add
Wiz
CVE-2026-3203 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-3203 [MEDIUM] CVE-2026-3203 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3203 :
Wireshark vulnerability analysis and mitigation
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Source : NVD
## 7.5
Score
Published February 25, 2026
Severity HIGH
CNA Score 5.5
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon
libvirt-daemon-config-nwfilter
Sources
Alpine 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 13, 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Echo Seve
Wiz
CVE-2026-0962 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-0962 [MEDIUM] CVE-2026-0962 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0962 :
Wireshark vulnerability analysis and mitigation
SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
Source : NVD
## 6.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-daemon-hooks
libwiretap16
Sources
Alpine 3.20, 3.21, edge Severity MEDIUM No Fix Added at: Jan 22, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Jan 18, 2026
Debian 13, 14 Severity
2026-02-25
Published