DSA-6471-1 wireshark - security update
Multiple vulnerabilities have been discocvered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6471-1
CSIRTS triage
- What
- Multiple vulnerabilities in network protocol parsing enable denial of service or arbitrary code execution.
- Who is affected
- Wireshark users analyzing untrusted or malicious network traffic captures.
- Urgency
- Medium-High; arbitrary code execution via malformed protocol data requires network packet processing.
- Action
- Apply Debian security update DSA-6471-1 or upgrade Wireshark to patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Wireshark
Get an email when a new Wireshark advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00382.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-151630.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151640.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151660.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151670.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151680.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151690.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151700.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151710.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151720.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-151740.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Wireshark: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-76929: Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servicenvd
- highCVE-2026-76928: X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servic…nvd
- mediumCVE-2026-76927: H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servicenvd
- lowCVE-2026-76926: BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ser…nvd
- mediumCVE-2026-76924: Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servi…nvd
- mediumCVE-2026-76923: Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows de…nvd
- mediumCVE-2026-76922: Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den…nvd
- mediumCVE-2026-76921: CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servicenvd
- mediumCVE-2026-76920: 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servic…nvd
- mediumCVE-2026-76919: ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servicenvd
- mediumCVE-2026-76918: SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of servicenvd
More from Debian Security Advisories
- unknownDSA-6489-1 gst-plugins-base1.0 - security update2026-09-08
- unknownDSA-6488-1 jbig2dec - security update2026-09-07
- unknownDSA-6487-1 strongswan - security update2026-09-07
- unknownDSA-6485-1 tryton-server - security update2026-09-06
- unknownDSA-6486-1 libde265 - security update2026-09-06