Wireshark disclosed CVE-2026-15168, an information disclosure flaw in its BLF file parser that can expose uninitialized heap memory when a user opens a specially crafted packet trace. The bug stems from the BLF zlib LogContainer reader trusting an attacker-controlled uncompressed_size value, allocating a non-zeroed buffer of that size, and treating Z_STREAM_END as success without confirming that zlib actually produced the claimed number of bytes.
As a result, subsequent BLF object readers can consume unread portions of the buffer as if they were valid packet data, leaking heap contents in decoded output, including through tshark and potentially sharkd responses. Wireshark said the issue affects versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16 and was fixed in 4.6.7 and 4.4.17; the flaw was reported by Thai Duong Tran, and the vendor said no exploits were known at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On July 8, 2026, Wireshark published security advisory wnpa-sec-2026-60 for CVE-2026-15168, describing a BLF parser information disclosure issue caused by reading uninitialized memory. The advisory said the flaw affected versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, with fixes released in 4.6.7 and 4.4.17.
Thai Duong Tran reported a vulnerability in Wireshark's BLF zlib LogContainer reader that could disclose uninitialized heap memory when parsing a crafted BLF file. The issue was documented in Wireshark GitLab issue #21361, including proof-of-concept details and affected versions.
After disclosure, Wireshark assigned the issue CVE-2026-15168 and merged fixes to validate that the actual decompressed size matches the claimed size in BLF zlib LogContainers. The merged fixes were referenced as merge requests including !25501 and !25524.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.