Wireshark disclosed CVE-2026-6870, a crash-causing flaw in its GSM RP protocol dissector that can be triggered by a malformed packet on the network or by opening a crafted packet capture file. The bug was traced to a stale global g_tree in packet-gsm_a_rp.c when RP User-Data is dissected through the BSSMAP VGCS-SMS path, leading to a heap-buffer-overflow read and application crash in Wireshark and TShark.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
On April 29, 2026, Wireshark published security notice wnpa-sec-2026-43 for CVE-2026-6870, describing a GSM RP protocol dissector crash. The advisory said affected versions include 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and that malformed network traffic or packet trace files could trigger the crash.
Wireshark said the vulnerability was fixed in versions 4.6.5 and 4.4.15 and advised users to upgrade. The advisory also noted that no exploits were known at the time of publication.
The Wireshark GSM RP dissector flaw was assigned identifier CVE-2026-6870. The assignment was noted in the GitLab issue and reflected in the CVE record.
Upstream maintainers merged fixes titled "GSM RP: Don't use a global" and closed the Wireshark issue as Done. The issue record links the closure to commit 6fc954bb and merge requests !24357, !24364, and !24365.
A vulnerability in Wireshark/TShark's GSM RP dissector was reported in GitLab issue #21189. The report described a stale global g_tree in packet-gsm_a_rp.c that can cause a heap-buffer-overflow read and crash when RP User-Data is dissected via BSSMAP VGCS-SMS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcewireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.