Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76880

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a specially crafted Universal Mobile Telecommunications System (UMTS) RRC protocol packet. The flaw resides in the UMTS RRC protocol dissector, which can lead to a crash of the Wireshark application. This can disrupt network analysis operations.

Отчет

This Moderate impact denial of service flaw in Wireshark's UMTS RRC protocol dissector can be triggered by processing a specially crafted packet. While exploitable by a remote attacker, successful exploitation requires a user to either open a malicious capture file or actively capture network traffic containing the crafted packet. This limits the attack surface to scenarios where Wireshark is actively used for network analysis.

Меры по смягчению последствий

To mitigate this issue, avoid opening untrusted capture files or analyzing untrusted live network traffic with Wireshark. Users should only process network data from trusted sources to prevent potential denial of service attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkAffected
Red Hat Enterprise Linux 6wiresharkNot affected
Red Hat Enterprise Linux 7wiresharkAffected
Red Hat Enterprise Linux 8wiresharkAffected
Red Hat Enterprise Linux 9wiresharkAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2520088wireshark: Wireshark: Denial of Service via RRC protocol dissector out-of-bounds write

EPSS

Процентиль: 20%
0.00279
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 дней назад

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 7.5
nvd
8 дней назад

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 7.5
debian
8 дней назад

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...

CVSS3: 7.5
github
8 дней назад

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

EPSS

Процентиль: 20%
0.00279
Низкий

5.5 Medium

CVSS3