#1149644 wireshark: CVE-2026-95386 CVE-2026-95387 CVE-2026-95388 CVE-2026-95389 CVE-2026-95390 CVE-2026-95391 CVE-2026-95392 CVE-2026-95393 CVE-2026-95394 CVE-2026-95395 CVE-2026-96415 CVE-2026-96416 CVE-2026-96417 CVE-2026-96418 CVE-2026-96419 CVE-2026-96420 CVE-2026-96421 CVE-2026-96422 CVE-2026-96423

Package:
src:wireshark
Source:
src:wireshark
Submitter:
Moritz Mühlenhoff
Date:
2026-10-07 20:29:03 UTC
Severity:
normal
Tags:
#1149644#5
Date:
2026-10-01 20:55:23 UTC
From:
To:
Hi,

The following vulnerabilities were published for wireshark.

We should also ship 4.4.19 via trixie-securiy, could someone of
the Wireshark maintainers please prepare an update?`


CVE-2026-95386[0]:
| TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of
| service

https://www.wireshark.org/security/wnpa-sec-2026-94
https://gitlab.com/wireshark/wireshark/-/issues/21501

CVE-2026-95387[1]:
| SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-97
https://gitlab.com/wireshark/wireshark/-/issues/21487

CVE-2026-95388[2]:
| Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows
| denial of service

https://www.wireshark.org/security/wnpa-sec-2026-101
https://gitlab.com/wireshark/wireshark/-/issues/21545

CVE-2026-95389[3]:
| SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-93
https://gitlab.com/wireshark/wireshark/-/issues/21481

CVE-2026-95390[4]:
| PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of
| service

https://www.wireshark.org/security/wnpa-sec-2026-95
https://gitlab.com/wireshark/wireshark/-/issues/21503

CVE-2026-95391[5]:
| ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial
| of service

https://www.wireshark.org/security/wnpa-sec-2026-92
https://gitlab.com/wireshark/wireshark/-/merge_requests/26096

CVE-2026-95392[6]:
| MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://gitlab.com/wireshark/wireshark/-/issues/21549
https://gitlab.com/wireshark/wireshark/-/issues/21550

CVE-2026-95393[7]:
| CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-99
https://gitlab.com/wireshark/wireshark/-/issues/21510

CVE-2026-95394[8]:
| Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8
| and 4.4.0 to 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-98
https://gitlab.com/wireshark/wireshark/-/issues/21523

CVE-2026-95395[9]:
| IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0
| to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-96
https://gitlab.com/wireshark/wireshark/-/issues/21492

CVE-2026-96415[10]:
| Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and
| 4.4.0 to 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-110
https://gitlab.com/wireshark/wireshark/-/issues/21589

CVE-2026-96416[11]:
| IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to
| 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-109
https://gitlab.com/wireshark/wireshark/-/issues/21564

CVE-2026-96417[12]:
| RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-104
https://gitlab.com/wireshark/wireshark/-/issues/21574

CVE-2026-96418[13]:
| TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to
| 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-107
https://gitlab.com/wireshark/wireshark/-/issues/21565

CVE-2026-96419[14]:
| Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows
| denial of service and possible code execution

https://www.wireshark.org/security/wnpa-sec-2026-106
https://gitlab.com/wireshark/wireshark/-/issues/21553

CVE-2026-96420[15]:
| Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-105
https://gitlab.com/wireshark/wireshark/-/issues/21541

CVE-2026-96421[16]:
| USB HID protocol dissector infinite loop and memory leak in 4.6.0 to
| 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-103
https://gitlab.com/wireshark/wireshark/-/issues/21566

CVE-2026-96422[17]:
| Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to
| 4.4.18 allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-102
https://gitlab.com/wireshark/wireshark/-/issues/21525

CVE-2026-96423[18]:
| X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18
| allows denial of service

https://www.wireshark.org/security/wnpa-sec-2026-108
https://gitlab.com/wireshark/wireshark/-/issues/21563


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-95386
https://www.cve.org/CVERecord?id=CVE-2026-95386
[1] https://security-tracker.debian.org/tracker/CVE-2026-95387
https://www.cve.org/CVERecord?id=CVE-2026-95387
[2] https://security-tracker.debian.org/tracker/CVE-2026-95388
https://www.cve.org/CVERecord?id=CVE-2026-95388
[3] https://security-tracker.debian.org/tracker/CVE-2026-95389
https://www.cve.org/CVERecord?id=CVE-2026-95389
[4] https://security-tracker.debian.org/tracker/CVE-2026-95390
https://www.cve.org/CVERecord?id=CVE-2026-95390
[5] https://security-tracker.debian.org/tracker/CVE-2026-95391
https://www.cve.org/CVERecord?id=CVE-2026-95391
[6] https://security-tracker.debian.org/tracker/CVE-2026-95392
https://www.cve.org/CVERecord?id=CVE-2026-95392
[7] https://security-tracker.debian.org/tracker/CVE-2026-95393
https://www.cve.org/CVERecord?id=CVE-2026-95393
[8] https://security-tracker.debian.org/tracker/CVE-2026-95394
https://www.cve.org/CVERecord?id=CVE-2026-95394
[9] https://security-tracker.debian.org/tracker/CVE-2026-95395
https://www.cve.org/CVERecord?id=CVE-2026-95395
[10] https://security-tracker.debian.org/tracker/CVE-2026-96415
https://www.cve.org/CVERecord?id=CVE-2026-96415
[11] https://security-tracker.debian.org/tracker/CVE-2026-96416
https://www.cve.org/CVERecord?id=CVE-2026-96416
[12] https://security-tracker.debian.org/tracker/CVE-2026-96417
https://www.cve.org/CVERecord?id=CVE-2026-96417
[13] https://security-tracker.debian.org/tracker/CVE-2026-96418
https://www.cve.org/CVERecord?id=CVE-2026-96418
[14] https://security-tracker.debian.org/tracker/CVE-2026-96419
https://www.cve.org/CVERecord?id=CVE-2026-96419
[15] https://security-tracker.debian.org/tracker/CVE-2026-96420
https://www.cve.org/CVERecord?id=CVE-2026-96420
[16] https://security-tracker.debian.org/tracker/CVE-2026-96421
https://www.cve.org/CVERecord?id=CVE-2026-96421
[17] https://security-tracker.debian.org/tracker/CVE-2026-96422
https://www.cve.org/CVERecord?id=CVE-2026-96422
[18] https://security-tracker.debian.org/tracker/CVE-2026-96423
https://www.cve.org/CVERecord?id=CVE-2026-96423

Please adjust the affected versions in the BTS as needed.

#1149644#14
Date:
2026-10-07 20:27:21 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149644@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Matheus Polkorny <polkorny@debian.org> (supplier of updated wireshark package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 23:53:49 -0300
Source: wireshark
Architecture: source
Version: 4.6.9-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Matheus Polkorny <polkorny@debian.org>
Closes: 1142268 1144924 1149644
Changes:
 wireshark (4.6.9-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release (Closes: #1142268, #1144924, #1149644)
     - CVE-2026-15163: Multiple loops in dissectors, allows DoS
     - CVE-2026-15164: Crash in ciscodump, allows DoS
     - CVE-2026-15165: TLS ECH decryptor crash, allows DoS
     - CVE-2026-15166: IEEE 802.11 dissector crash, allows DoS
     - CVE-2026-15167: DBS Etherwatch parser crash, allows DoS
     - CVE-2026-15168: BLF parser, allows information disclosure
     - CVE-2026-15169: UMTS FP dissector crash, allows DoS
     - CVE-2026-15170: Z39.50 dissector crash, allows DoS
     - CVE-2026-15171: SSH dissector crash, allows DoS
     - CVE-2026-15172: FMP/NOTIFY dissector crash, allows DoS
     - CVE-2026-15173: pcapng file parser crash, allows DoS
     - CVE-2026-15174: Catapult DCT2000 dissector crash, allows DoS
     - CVE-2026-19694: TTX Logger file parser crash, allows DoS
     - CVE-2026-19695: Gammu DCT3 trace file parser crash, allows DoS
     - CVE-2026-19696: Ixia IxVeriWave file parser crash, allows DoS
     - CVE-2026-76879: C12.22 dissector crash, allows DoS
     - CVE-2026-76880: RRC dissector crash, allows DoS
     - CVE-2026-76881: CMS dissector crash, allows DoS
     - CVE-2026-76882: Bluetooth Attribute dissector crash, allows DoS
     - CVE-2026-76883: Catapult DCT2000 parser crash, allows DoS
     - CVE-2026-76884: ERF parser crash, allows DoS
     - CVE-2026-76885: Tektronix K12xx parser crash, allows DoS
     - CVE-2026-76886: C12.22 dissector crash, allows DoS
     - CVE-2026-76887: Dissection engine crash, allows DoS
     - CVE-2026-76888: RDP dissector crash, allows DoS
     - CVE-2026-76889: UMTS FP dissector crash, allows DoS
     - CVE-2026-76890: Crash in sharkd, allows DoS
     - CVE-2026-76891: Crash in sharkd, allows DoS
     - CVE-2026-76917: Bluetooth AVRCP dissector crash, allows DoS
     - CVE-2026-76918: SSH dissector crash, allows DoS
     - CVE-2026-76919: ESS dissector crash, allows DoS
     - CVE-2026-76920: 3gpp phone log parser crash, allows DoS
     - CVE-2026-76921: CMS dissector crash, allows DoS
     - CVE-2026-76922: Bluetooth BR/EDR FHS dissector crash, allows DoS
     - CVE-2026-76923: Bluetooth HFP dissector crash, allows DoS
     - CVE-2026-76924: Kerberos dissector crash, allows DoS
     - CVE-2026-76926: BUSMASTER parser abnormal exit, allows DoS
     - CVE-2026-76927: H.245 dissector crash, allows DoS
     - CVE-2026-76928: X.509IF dissector crash, allows DoS
     - CVE-2026-76929: Pcapng parser crash, allows DoS
     - CVE-2026-95386: TTL file parser infinite loop, allows DoS
     - CVE-2026-95387: SPDY dissector crash, allows DoS
     - CVE-2026-95388: Crash in sharkd, allows DoS
     - CVE-2026-95389: SCTP dissector crash, allows DoS
     - CVE-2026-95390: PEAK CAN TRC file parser crash, allows DoS
     - CVE-2026-95391: ZigBee ZCL protocol dissector crash, allows DoS
     - CVE-2026-95392: MBIM dissector crash, allows DoS
     - CVE-2026-95393: CSN.1 dissector crash, allows DoS
     - CVE-2026-95394: MNM parser large loop, allows DoS
     - CVE-2026-95395: IEEE C37.118 dissector memory leak, allows DoS
     - CVE-2026-96415: Catapult DCT2000 dissector crash, allows DoS
     - CVE-2026-96416: IEEE 802.11 dissector crash, allows DoS
     - CVE-2026-96417: RF4CE dissector crash, allows DoS
     - CVE-2026-96418: TIFF dissector infinite loop, allows DoS
     - CVE-2026-96419: Profile import crash, possible code execution
     - CVE-2026-96420: Toshiba parser crash, allows DoS
     - CVE-2026-96421: USB HID dissector memory leak, allows DoS
     - CVE-2026-96422: Frame metadissector crash, allows DoS
     - CVE-2026-96423: X11 dissector crash, allows DoS
   * d/libwireshark19.symbols: Update symbols file
Checksums-Sha1:
 931363145eba53bc8cc0b844e18395d2e0e0cdb7 3698 wireshark_4.6.9-1.dsc
 4c2ba4500ad91708080e77e738b601046aed9ece 61166804 wireshark_4.6.9.orig.tar.bz2
 386144ff4abb9f7847c5eb3bb3267d4c5dade890 91640 wireshark_4.6.9-1.debian.tar.xz
 62316a60766fef5deb0c6fc9d692db2add409739 26464 wireshark_4.6.9-1_amd64.buildinfo
Checksums-Sha256:
 420344d5e08fb30427f0b805d809bfcda33f4d5ba3365a1346eb78c7ddf156b1 3698 wireshark_4.6.9-1.dsc
 ac98b261c824930442f9e755011a96b78e58bd09dc6a33507b1819f44222f262 61166804 wireshark_4.6.9.orig.tar.bz2
 03d12852d31f58c652bc84c60bf5cf3a95d02d5d66771372b8792eb522893e1d 91640 wireshark_4.6.9-1.debian.tar.xz
 f0db61cc4042549a441a16693196b456384415479f64a8d0f61cb097b28f4274 26464 wireshark_4.6.9-1_amd64.buildinfo
Files:
 9bf0b8676a86c6e31d6deaae5807b1d9 3698 net optional wireshark_4.6.9-1.dsc
 78cbfb1fbc0e55fb38fc86a45afa0114 61166804 net optional wireshark_4.6.9.orig.tar.bz2
 0b1057b655582203234060876632f5a5 91640 net optional wireshark_4.6.9-1.debian.tar.xz
 9bdbef9d576927a0546d2b45d0c311c4 26464 net optional wireshark_4.6.9-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEcRD/fHLtdypUR2KKShyoWjj77loFAmrGoNoACgkQShyoWjj7
7loT2xAAhJ8ojkejsXUuEL+E2rGCQv4s1d6vox4yq2ZXqVQLrW0FiIUxHvIqK80y
EZioH0Ewo1WUvEsfk232bqUuMGeNlMn1FfcRILG845AsoUg+9dT1A0wP5h6/jjQM
Lq9AjtP/jTfMZ8RDJmpheaDRa3JusbgDxTqx7ahZGzNasu75eq8hFgZHyfHrBKRB
/eAx6FE3nncPpAAPi3KpRK9TrNkeuWKG9WOE6DAv2ST97/Sl91qQTU5QRcN9u42i
jIItOBhRjyUDTdtjP6Hr8/1iaRpFKYbmSgYlNKu5b1M3hORtVb6wgGO8pE4Y0KDx
v2CbEBf7wMWcVGXbGeaeeSywzPpi+mTvMYf+6R14UWrmOIzi0mtycE8M6dQV/PG3
kwKVkhEkDGkGe5OB9jOH88Uqx0JQNYdjR5CQ9K4hsxZZyMi5j/nBsSkXReklt5fw
k4iUdasjd0pZL5cM5wotrSo5/JPJ93meHDZNSpjyJvg6+KrbeC4ePr5lVfJ2gbKp
Jsi0xGUrpQlDg14gkeWkEbHcuGKzP0wUzMheReoh2SxAI+eQv/EobYhRJlQcnmLI
oFhUkmXZYtz9/3Y2eY7gMGejhJHgwiC8U5ADy7M2Hte79Mp4w6E/+YIbcjAXrnTp
rkKZZBmaqozF3b3esX4EEfn1P6TTA4wVEf/2Pw03OaG8O2fEEmE=
=VMAv
-----END PGP SIGNATURE-----