Wireshark disclosed and fixed CVE-2026-15167, a heap buffer overflow in the DBS Etherwatch capture file parser that can be triggered by opening a crafted packet trace file. The flaw was reported in wiretap/dbs-etherwatch.c, where bytes from a textual hex dump were written into a record buffer without per-write bounds checks, allowing attacker-controlled data to be written past a heap allocation. The issue was reproduced deterministically with AddressSanitizer and was considered especially serious for libwiretap in headless parsing workflows, while desktop users could also be affected by simply opening a malicious file.
According to Wireshark's advisory, the vulnerability can crash the application and cause a denial-of-service condition. Affected releases include Wireshark 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and fixes were released in 4.6.7 and 4.4.17. The original issue was tracked in GitLab and later closed after the fix was merged, and Wireshark credited Nguyen Huu Trung with discovering the bug while noting that no public exploits were known at the time of disclosure.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security notice wnpa-sec-2026-62 for CVE-2026-15167, describing a DBS Etherwatch file parser crash that can be triggered by opening a malformed packet trace file. The advisory said versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16 were affected, and that the issue was fixed in 4.6.7 and 4.4.17.
NGUYEN Huu Trung reported a heap buffer overflow in Wireshark's DBS Etherwatch capture file parser, affecting the current master branch verified at Wireshark 4.7.2. The report included a technical write-up, proof-of-concept files, and AddressSanitizer output showing deterministic heap-buffer-overflow reproduction.
The DBS Etherwatch parser vulnerability was assigned CVE-2026-15167. The CVE assignment was later noted on the GitLab issue and referenced in Wireshark's security advisory.
Wireshark fixed the DBS Etherwatch parser vulnerability through merge request !25436, titled "wiretap: DBS Etherwatch: Ensure buffer has slack for an extra line." After the merge, the GitLab issue tracking the flaw was closed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.