Wireshark disclosed a high-severity denial-of-service flaw in its X.509IF protocol dissector that can cause both Wireshark and TShark to crash while dissecting malformed traffic or packet capture files. The bug, assigned CVE-2026-76928, stems from nested DistinguishedName decoding that corrupts DN/RDN formatting state and leads to a NULL pointer dereference in generated X.509IF parsing code using file-static state such as last_rdn_buf.
Researchers from Aisle Research, O2Lab, and TAMU reported that the crash can be triggered by a crafted LDAP ExtendedRequest carrying a nested id-at-member value (OID 2.5.4.31), without authentication, a bind, a TCP session, or cryptographic validation. Wireshark maintainers reproduced the issue, confirmed it as a regression, and released fixes that preserve parser state across nested decoding and exception unwinds; affected versions include 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17, with patches available in 4.6.8 and 4.4.18.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security notice wnpa-sec-2026-87 disclosing the X.509IF protocol dissector crash vulnerability and stating it affects versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17. The advisory says the issue was fixed in versions 4.6.8 and 4.4.18 and that no exploits were known at the time of publication.
On its GitLab issue tracker, Wireshark published issue #21469 documenting the X.509IF denial-of-service vulnerability, including reproduction details, affected revisions, and the merged fix status. The issue states the bug can be triggered without authentication, a bind, a TCP session, or cryptographic validation.
Gerald Combs confirmed that the Wireshark X.509IF dissector crash vulnerability was assigned CVE-2026-76928. The issue was tracked as Wireshark issue #21469.
Wireshark merged fixes for the X.509IF DN/RDN formatting-state bug in merge requests !26046, !26047, and !26048. The remediation preserves parser state across nested decoding and exception unwinds to prevent the crash.
Researchers from Aisle Research, O2Lab, and TAMU reported a high-severity NULL pointer dereference in Wireshark's X.509IF dissector that can be triggered by malformed nested DistinguishedName data and cause Wireshark or TShark to crash during packet dissection. Wireshark maintainers reproduced the issue and identified it as a regression affecting current master and release-4.2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.