Wireshark disclosed CVE-2026-76919, a flaw in its ESS protocol dissector that can crash the application when it processes malformed BER BIT STRING data. The bug stems from generated ESS dissector code that can pass an uninitialized tvbuff_t * pointer into attribute-flag post-processing after BER decoding paths return without assigning it; a crafted zero-length BIT STRING such as:
03 00
can trigger a dissector exception, abort, crash, or unsafe native memory access in Wireshark or TShark.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-12, Wireshark published security notice wnpa-sec-2026-86 for an ESS protocol dissector crash vulnerability affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17. The advisory credited Aisle Research, O2Lab, and Texas A&M University researchers and said Wireshark was unaware of any exploits.
Wireshark said the ESS dissector crash vulnerability was fixed in versions 4.6.8 and 4.4.18, and advised users to upgrade to those releases or later. The flaw could be triggered by malformed network traffic or a crafted capture file.
The GitLab issue states the vulnerability was fixed and closed through merged merge requests and commit affa11c6. The remediation initializes the attributes pointer to NULL and only calls ess_dissect_attribute_flags() when BER decoding produced a valid TVB.
A GitLab issue documented CVE-2026-76919, a flaw in Wireshark's ESS dissector where malformed BER BIT STRING data could cause an uninitialized tvbuff_t pointer to be used during attribute-flag dissection. The issue states it was reported by AISLE Security and includes technical details and a proposed fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.