Wireshark disclosed CVE-2026-7376, a denial-of-service flaw in the sharkd utility caused by a NULL pointer dereference when the comment parameter is omitted from setcomment. The issue was tracked as Wireshark issue #21206 and reported by Alexandre de Oliveira, with the bug leading to a crash rather than code execution.
The vulnerability affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Wireshark said the flaw was fixed in 4.6.5 and 4.4.15, and noted that no exploits are known at the time of disclosure.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory WNPA-SEC-2026-48 for CVE-2026-7376, a sharkd utility crash issue affecting versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The company said the flaw was fixed in versions 4.6.5 and 4.4.15, credited Alexandre de Oliveira with discovery, and stated it knew of no exploits.
A GitLab issue was opened for a NULL pointer dereference in sharkd's setcomment handling when the comment parameter is omitted. This issue is tracked as Wireshark issue 21206.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.