Wireshark disclosed and fixed memory-safety flaws in its UMTS FP dissector that could be triggered by malformed network traffic or crafted packet capture files opened in Wireshark, tshark, or sharkd. One issue, tracked as CVE-2026-15169 and published as wnpa-sec-2026-59, stems from dissect_e_dch_t2_or_common_channel_info() writing past a static subframes[16] array in the UMTS FP E-DCH Type-2 parser, enabling memory corruption and at minimum a reliable denial of service. Wireshark said the bug affects versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and was fixed in 4.6.7 and 4.4.17.
A related flaw in the same function was later assigned CVE-2026-76889 after researchers showed that a packet-controlled continuation flag could keep MAC-is descriptor parsing running beyond 16 entries, causing fixed-array out-of-bounds writes to mac_is_lchid[pdu_no][16] and mac_is_length[pdu_no][16]. The bugs were reproduced with sanitizers against development and pre-release builds, and Wireshark closed the reports after merging fixes including !25692 for UMTS-FP limits checking and !25780 for the MAC-is descriptor handling issue. The disclosures indicate the vulnerabilities could be exploited through injected malformed packets or malicious trace files, although no public exploits were reported at disclosure time.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
The reporter sent a confidential reproducer archive for a separate UMTS FP memory-safety issue to security@wireshark.org and requested credit under the name Jaime Cavero. The issue involved fixed-array out-of-bounds writes in MAC-is SDU descriptor parsing.
On July 8, 2026, Wireshark published advisory wnpa-sec-2026-59 for a UMTS FP protocol dissector crash tracked as CVE-2026-15169. The advisory said affected versions were 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and that fixes were available in 4.6.7 and 4.4.17.
Gerald Combs stated that the later UMTS FP MAC-is descriptor count issue was assigned CVE-2026-76889. The flaw affected the dissector function dissect_e_dch_t2_or_common_channel_info() and could be reproduced with a synthetic capture under UBSan.
Wireshark closed the later UMTS FP issue after merge request !25780, titled "UMTS-FP: More bounds checking against subframes[]," was merged. This addressed fixed-array out-of-bounds writes caused by excessive MAC-is SDU descriptors.
Wireshark merged merge request !25692, titled "UMTS-FP: Check some limits (fp channels and number of mac pdus)," to address the UMTS FP limits-checking flaw reported in issue 21398. The issue was later assigned CVE-2026-15169.
A security issue in Wireshark's UMTS FP E-DCH Type-2 dissector was found by Anthropic using Claude and manually validated and reported by Ada Logics under security issue ANT-2026-JVHH18M7. The report states disclosure timing was deferred to Wireshark's security team under a coordinated disclosure process.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
gitlab.com
Open sourcewireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.