Wireshark disclosed CVE-2026-3201, a denial-of-service flaw in its USB HID dissector that can cause excessive memory consumption and make Wireshark or TShark hang or crash. The bug is tied to parse_report_descriptor() in packet-usb-hid.c, where crafted HID USAGE_MINIMUM and USAGE_MAXIMUM values can drive uncontrolled growth through wmem_array_grow() when a malformed pcap or pcapng file is processed.
The issue, tracked as Wireshark issue #20972, was described as a regression of an earlier fix that had added a descriptor count limit. Wireshark said the vulnerability affects versions 4.6.0 through 4.6.3 and 4.4.0 through 4.4.13, and can be triggered either by injecting a malformed packet or by convincing a user to open a malicious trace file. The vendor credited Qi Kery with discovery, said it was unaware of active exploitation, and released fixes in 4.6.4 and 4.4.14.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark stated that the USB HID memory exhaustion issue was fixed in versions 4.6.4 and 4.4.14, and recommended users upgrade to those releases or later. The GitLab issue also indicates the bug was closed after related merge requests were merged.
Wireshark published security notice wnpa-sec-2026-05 for CVE-2026-3201, disclosing a USB HID dissector memory exhaustion vulnerability affecting versions 4.6.0 through 4.6.3 and 4.4.0 through 4.4.13. The advisory said Wireshark was unaware of active exploits and credited Qi Kery with discovering the issue.
A GitLab issue documented a denial-of-service vulnerability in Wireshark's USB HID dissector, where crafted HID USAGE_MINIMUM and USAGE_MAXIMUM values in a pcap or pcapng file could trigger excessive memory allocation in parse_report_descriptor(). The issue was tracked as Wireshark issue 20972 and later assigned CVE-2026-3201.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcecve.mitre.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.