PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76926 Wireshark Foundation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T23:16:21.320Z and has not been modified since then. The BUSMASTER file parser in versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 is vulnerable to a denial of service attack due to an abnormal exit. This vulnerability has been assigned a CVSS score of 3.1 and a CVSS severity of LOW. The vulnerability is caused by the file parser's inability to handle specific files, leading to an abnormal exit and potential denial of service. Users of BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 should review and apply vendor patches to mitigate potential denial of service attacks. Additionally, operators, administrators, and security teams responsible for the affected systems should be aware of the vulnerability and take necessary precautions to prevent exploitation. Vulnerability management and security teams should prioritize patching and monitoring of affected systems. Evidence from official CVE and NVD sources indicates a denial of service vulnerability in BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. Further review of vendor advisories and exploit mitigations is recommended. Limited information is available about potential exploits or attacks in the wild.

Vendor
Wireshark Foundation
Product
Wireshark
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-01
Advisory published
2026-08-19
Advisory updated
2026-09-01

Who should care

Users of BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 should review and apply vendor patches to mitigate potential denial of service attacks. Additionally, operators, administrators, and security teams responsible for the affected systems should be aware of the vulnerability and take necessary precautions to prevent exploitation. Vulnerability management and security teams should prioritize patching and monitoring of affected systems.

Technical summary

The BUSMASTER file parser in versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 is vulnerable to a denial of service attack due to an abnormal exit. This vulnerability has been assigned a CVSS score of 3.1 and a CVSS severity of LOW. The vulnerability is caused by the file parser's inability to handle specific files, leading to an abnormal exit and potential denial of service.

Defensive priority

Low-priority defensive review recommended due to limited attack surface.

Recommended defensive actions

  • Review and apply vendor patches for BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
  • Monitor system logs for abnormal exits of BUSMASTER file parser
  • Implement compensating controls to limit potential denial of service attacks

Evidence notes

Evidence from official CVE and NVD sources indicates a denial of service vulnerability in BUSMASTER file parser versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. Further review of vendor advisories and exploit mitigations is recommended. The vulnerability has a CVSS score of 3.1 and a CVSS severity of LOW. BUSMASTER file parser abnormal exit can be triggered by a specific file, potentially leading to a denial of service attack. Limited information is available about potential exploits or attacks in the wild.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76926 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76926

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76926 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76926

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.