PatchSiren cyber security CVE debrief
CVE-2026-76926 Wireshark Foundation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T23:16:21.320Z and has not been modified since then. The BUSMASTER file parser in versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 is vulnerable to a denial of service attack due to an abnormal exit. This vulnerability has been assigned a CVSS score of 3.1 and a CVSS severity of LOW. The vulnerability is caused by the file parser's inability to handle specific files, leading to an abnormal exit and potential denial of service. Users of BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 should review and apply vendor patches to mitigate potential denial of service attacks. Additionally, operators, administrators, and security teams responsible for the affected systems should be aware of the vulnerability and take necessary precautions to prevent exploitation. Vulnerability management and security teams should prioritize patching and monitoring of affected systems. Evidence from official CVE and NVD sources indicates a denial of service vulnerability in BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. Further review of vendor advisories and exploit mitigations is recommended. Limited information is available about potential exploits or attacks in the wild.
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-01
Who should care
Users of BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 should review and apply vendor patches to mitigate potential denial of service attacks. Additionally, operators, administrators, and security teams responsible for the affected systems should be aware of the vulnerability and take necessary precautions to prevent exploitation. Vulnerability management and security teams should prioritize patching and monitoring of affected systems.
Technical summary
The BUSMASTER file parser in versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 is vulnerable to a denial of service attack due to an abnormal exit. This vulnerability has been assigned a CVSS score of 3.1 and a CVSS severity of LOW. The vulnerability is caused by the file parser's inability to handle specific files, leading to an abnormal exit and potential denial of service.
Defensive priority
Low-priority defensive review recommended due to limited attack surface.
Recommended defensive actions
- Review and apply vendor patches for BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
- Monitor system logs for abnormal exits of BUSMASTER file parser
- Implement compensating controls to limit potential denial of service attacks
Evidence notes
Evidence from official CVE and NVD sources indicates a denial of service vulnerability in BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. Further review of vendor advisories and exploit mitigations is recommended. The vulnerability has a CVSS score of 3.1 and a CVSS severity of LOW. BUSMASTER file parser abnormal exit can be triggered by a specific file, potentially leading to a denial of service attack. Limited information is available about potential exploits or attacks in the wild.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76926 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76926
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76926 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76926
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gitlab.com/wireshark/wireshark/-/work_items/21435
[email protected] - Exploit, Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.wireshark.org/security/wnpa-sec-2026-70.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.