Wireshark disclosed and patched a high-severity vulnerability in its C12.22 protocol dissector that can crash the application when processing malformed traffic or packet captures. The flaw, tracked as CVE-2026-76886 and covered by advisory wnpa-sec-2026-75, stems from the EAX/CMAC decryption path, where Eax_Decrypt() accepts 32-bit lengths but passes them into 16-bit CMAC helper logic, causing integer truncation, undersized heap allocation, and subsequent oversized memcpy() operations that lead to a heap-buffer overflow.
The vulnerable code path is reachable through reassembled C12.22 traffic over TCP/1153 when c1222.decrypt is enabled and a matching decryption-table entry exists; researchers reported that a crafted 65,576-byte MESSAGE can reliably trigger the crash. Wireshark said affected versions are 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17, with fixes released in 4.6.8 and 4.4.18 that reject oversized CMAC inputs before allocation. The issue was reported by researchers from Aisle Research, O2Lab, and TAMU, and Wireshark said no active exploits are known.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security advisory wnpa-sec-2026-75 for a C12.22 protocol dissector crash affecting versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17. The advisory states the issue is fixed in versions 4.6.8 and 4.4.18 and that no exploits are known.
On its issue tracker, Wireshark disclosed and documented the heap-buffer-overflow vulnerability in EAX/CMAC handling for large C12.22 cleartext-authentication payloads. The report included technical root-cause details, proof-of-concept artifacts, and confirmation that the patch prevented the ASan-detected crash.
Wireshark merged fixes that reject oversized CMAC inputs before allocation, preventing the heap overflow in EAX/CMAC processing. The issue was then closed with references to merge requests !25925, !25937, !25938, and commit 360bdc60.
Aisle Research reported a high-severity heap-buffer-overflow vulnerability in Wireshark's EAX/CMAC handling for large C12.22 cleartext-authentication payloads, later assigned CVE-2026-76886. The issue can be triggered via reassembled C12.22 traffic when decryption is enabled and a matching key entry exists.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.