PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9759 Wireshark Foundation CVE debrief

A denial-of-service vulnerability exists in the ROHC (Robust Header Compression) protocol dissector of Wireshark versions 4.6.0 through 4.6.5 and 4.4.0 through 4.4.15. The flaw can cause the dissector to crash when processing malformed ROHC traffic, resulting in loss of availability for the Wireshark application. The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and carries a CVSS 3.1 score of 5.5 (MEDIUM severity), with an attack vector that requires local access and user interaction. The vulnerability was published on 2026-05-27. No known exploitation in ransomware campaigns has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

Vendor
Wireshark Foundation
Product
Wireshark
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-06-01
Advisory published
2026-05-27
Advisory updated
2026-06-01

Who should care

Network administrators, security analysts, and incident responders who use Wireshark for packet analysis; organizations with security operations centers relying on Wireshark for traffic inspection; developers and QA teams using Wireshark in automated capture analysis pipelines

Technical summary

The ROHC (Robust Header Compression) protocol dissector in Wireshark contains a vulnerability that can trigger a crash when handling malformed packets. The affected versions span two release branches: 4.6.x (4.6.0 through 4.6.5) and 4.4.x (4.4.0 through 4.4.15). The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) indicates the attack requires local access and user interaction, with high impact to availability but no confidentiality or integrity impact. The underlying weakness is categorized as CWE-476 (NULL Pointer Dereference).

Defensive priority

medium

Recommended defensive actions

  • Upgrade Wireshark to a version outside the affected ranges (4.6.0-4.6.5, 4.4.0-4.4.15) once patches become available
  • Monitor Wireshark security advisories for updated fixed versions
  • Restrict capture file analysis to trusted sources and sandboxed environments where possible
  • Review and update endpoint security controls to detect unexpected Wireshark process terminations

Evidence notes

Vulnerability affects Wireshark ROHC dissector in specified version ranges. CVSS vector indicates local attack vector with user interaction required. CWE-476 classification suggests NULL pointer dereference as root cause.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9759 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9759

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9759 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9759

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.