Wireshark disclosed and fixed CVE-2026-15166, a stack-based buffer overflow in 802.11 EAPOL-Key decryption handling within Dot11DecryptDecryptKeyData(). The flaw stems from attacker-controlled EAPOL length fields reaching a memcpy into a fixed 1024-byte stack buffer without proper bounds checking on the decrypt path, allowing a malformed frame to corrupt the stack. The issue was reported in Wireshark's tshark processing and was reproduced with AddressSanitizer against commit b260b00b861aef491d11043d2a8c9dd2615cdb9e using the shipped wpa-Induction.pcap test capture.
Wireshark said the vulnerability affects versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and could let an attacker crash the application by convincing a user to open a malformed packet trace file. The original report said that, when WPA decryption is enabled and a valid Security Association exists for the BSSID, a single crafted EAPOL-Key frame can overflow the buffer by roughly 1000 bytes, creating potential RCE-class impact in addition to denial of service. Wireshark released fixes in 4.6.7 and 4.4.17 and said it was not aware of active exploitation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On July 8, 2026, Wireshark published advisory wnpa-sec-2026-57 for CVE-2026-15166, describing an IEEE 802.11 dissector crash affecting versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. Wireshark said it was unaware of exploits and released fixes in versions 4.6.7 and 4.4.17.
Ada Logics reported a stack-based buffer overflow in Wireshark's tshark 802.11 EAPOL-Key decryption path, where attacker-controlled length fields could drive a memcpy into a fixed 1024-byte stack buffer. The GitLab issue says the flaw was reproduced with AddressSanitizer and was later assigned CVE-2026-15166.
Wireshark closed the issue after merge request !25682 was merged, with additional related merge requests !25687 and !25688 also merged. The fix was described as checking for overly large values in EAPOL frames to prevent the overflow condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.