Wireshark disclosed CVE-2026-7378, a flaw in the sharkd utility that can cause the daemon to crash when filter state from a previously loaded capture file is reused in the same session. The issue affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and has been fixed in 4.6.5 and 4.4.15. Wireshark said it is not aware of active exploitation and credited the discovery to Alexandre de Oliveira.
The underlying bug was traced to a heap-buffer-overflow in sharkd's frames method, where cached filter bitmaps were kept in a session-wide hash table and not invalidated when a new capture file was loaded. That allowed a bitmap sized for one capture to be reused against a later capture with a different frame count, leading to an out-of-bounds read in sharkd_session_process_frames. Maintainers said triggering the flaw requires loading two captures in one session, reusing the same filter string, and making the second capture larger under specific matching conditions; the fix clears the filter table whenever a new file is loaded.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security advisory WNPA-SEC-2026-49 for CVE-2026-7378, a sharkd utility crash issue discovered by Alexandre de Oliveira. The advisory said affected versions were 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and that fixes were available in 4.6.5 and 4.4.15.
A GitLab issue documented a heap-buffer-overflow in sharkd caused by reuse of cached filter bitmaps across multiple capture-file loads in the same session. The report included reproduction details and noted remediation by clearing the filter table when loading a new file.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.