Wireshark disclosed CVE-2026-7379, a memory leak in the sharkd utility that can be triggered by repeated JSON-RPC capture load requests. The flaw stems from cf_open overwriting existing capture state without freeing prior wtap allocations, allowing memory use to grow without bound and potentially enabling resource exhaustion by an unauthenticated attacker with access to the sharkd socket. A public bug report demonstrated the issue with repeated pcap load operations under AddressSanitizer, which identified hundreds of leaked allocations.
The vendor published advisory wnpa-sec-2026-47 and said the issue affects Wireshark 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Wireshark reported no known exploitation in the wild, but warned that the bug may cause sharkd to consume excessive CPU resources. The issue was fixed by adding cleanup logic to close prior capture state, and users were advised to upgrade to 4.6.5 or 4.4.15.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
In the advisory, Wireshark said the vulnerability was fixed in versions 4.6.5 and 4.4.15 and advised users to upgrade to those releases or later. The issue was tracked as CVE-2026-7379.
Wireshark published security advisory wnpa-sec-2026-47 for CVE-2026-7379, stating that sharkd could leak memory and that no exploits were known in the wild. The advisory said affected versions were 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14.
A GitLab issue was filed describing a memory leak in sharkd's cf_open function, where repeated JSON-RPC load requests overwrite capture state without freeing prior allocations. The report said an unauthenticated attacker with access to the sharkd socket could trigger unbounded memory growth and denial of service.
The sharkd memory leak issue was subsequently assigned the identifier CVE-2026-7379. The CVE linked the vulnerability report to Wireshark's tracked security issue.
The issue was later closed after merge requests !24462, !24464, and !24465 were merged, implementing a skeleton of cf_close and calling it to prevent the leak. This resolved the bug tracked in issue 21214.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.