Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76884

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 3.3

Описание

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

A flaw was found in Wireshark. A remote attacker could exploit a buffer over-read vulnerability in the ERF (Extensible Record Format) file parser. This could lead to a denial of service, making the application unavailable to legitimate users.

Отчет

Red Hat Enterprise Linux 6 through 9 ship Wireshark versions 1.x through 3.x, which predate the introduction of the vulnerable code in version 4.4.0 and are therefore not affected by this flaw. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship Wireshark 4.4.2, which is within the affected range (4.4.0–4.4.17).

Меры по смягчению последствий

Avoid opening ERF (Extensible Record Format) capture files from untrusted or unknown sources in Wireshark.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wiresharkFix deferred
Red Hat Enterprise Linux 6wiresharkNot affected
Red Hat Enterprise Linux 7wiresharkNot affected
Red Hat Enterprise Linux 8wiresharkNot affected
Red Hat Enterprise Linux 9wiresharkNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-130
https://bugzilla.redhat.com/show_bug.cgi?id=2520077wireshark: Wireshark: Denial of Service via ERF file parser crash

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
7 дней назад

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
nvd
8 дней назад

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

CVSS3: 3.1
debian
8 дней назад

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den ...

CVSS3: 3.1
github
8 дней назад

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

3.3 Low

CVSS3