Wireshark disclosed and fixed a vulnerability in its UMTS RRC protocol dissector that could corrupt heap memory and crash the application during packet dissection. The flaw, assigned CVE-2026-76880, stemmed from a protocol-valid, packet-controlled RB-Identity value being stored in private state and later used directly as an array index, allowing writes beyond the intended bounds of rrc_ciphering_info.seq_no and corruption of adjacent heap-allocated ciphering state.
According to Wireshark's security advisory wnpa-sec-2026-88, the issue affects versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17, and was fixed in 4.6.8 and 4.4.18. An attacker could trigger the bug by injecting a malformed packet onto the network or by convincing a user to open a crafted packet capture file; Wireshark said no active exploits were known at the time of disclosure, and the underlying fix was tracked in the project's GitLab issue and resolved with commit a44c8dc0.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-12, Wireshark published security notice wnpa-sec-2026-88 describing an RRC protocol dissector crash issue that could be triggered by malformed network packets or crafted capture files. The notice said no exploits were known at publication time and recommended upgrading to fixed releases.
Wireshark fixed the RRC dissector vulnerability in versions 4.6.8 and 4.4.18. Affected versions were 4.6.0 through 4.6.7 and 4.4.0 through 4.4.17.
Wireshark tracked the vulnerability in GitLab issue 21478, titled "Fix potential heap corruption in UMTS RRC," and closed it with commit a44c8dc0 after related merge requests were merged. The issue was assigned CVE-2026-76880.
Aisle Research discovered a heap corruption vulnerability in Wireshark's UMTS RRC dissector, with credit given to Dmitrijs Trizna, Luigino Camastra, Ze Sheng of O2Lab and TAMU, and Igor Morgenstern. The flaw involved packet-controlled RB-Identity values being used as an array index, risking corruption of adjacent heap state during dissection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.