Wireshark disclosed and fixed CVE-2026-15170, a heap-buffer-overflow flaw in the Z39.50 MARC21 dissector's dissect_marc_record() function in packet-z3950.c. The bug was caused by a floor/ceil mismatch when calculating MARC directory entries: the code allocated a heap array based on floor division of the directory length by 12 bytes, but under attacker-controlled conditions could iterate one extra time and perform a 12-byte out-of-bounds heap write. The resulting memory corruption could crash Wireshark or tshark when processing a crafted packet capture or a malicious Z39.50 response on TCP port 210.
The issue affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, and was fixed in 4.6.7 and 4.4.17 under advisory wnpa-sec-2026-58. Wireshark said an attacker could trigger the flaw by injecting a malformed packet onto the network or by convincing a user to open a malicious trace file. The vulnerability was reproduced with Wireshark's fuzzshark harness and confirmed with AddressSanitizer, and the project said it was discovered by Claude and Ada Logics; no active exploits were known at disclosure.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security advisory wnpa-sec-2026-58 for CVE-2026-15170, describing a Z39.50 dissector crash affecting versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The advisory said the issue was fixed in versions 4.6.7 and 4.4.17 and recommended users upgrade.
A heap-buffer-overflow vulnerability in Wireshark's Z39.50 MARC21 dissector was reported in issue 21397, affecting the `dissect_marc_record()` function and enabling memory corruption or a crash via crafted traffic or capture files. The report included technical reproduction details, noted the issue was found by Anthropic using Claude and manually reviewed by Ada Logics, and proposed fixes for the parsing logic.
Wireshark later closed the GitLab issue after merging fixes, with John Thacker closing it via commit `c9bd4982`. Gerald Combs stated that the vulnerability had been assigned CVE-2026-15170.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.