Wireshark fixed a denial-of-service vulnerability in its Robust Header Compression (ROHC) protocol dissector. Specially crafted ROHC traffic injected onto a monitored network, or a malicious packet-capture file opened by an analyst, could crash the application. The flaw affects Wireshark versions 4.6.0 through 4.6.5 and 4.4.0 through 4.4.15; fixes are available in 4.6.6 and 4.4.16.
The underlying defect involved the ROHC uncompressed profile with a large context identifier (CID). A packet ending at the CID field could trigger a zero-length allocation that returned NULL, followed by a one-byte write to that pointer; subsequent length handling could also underflow into an effectively SIZE_MAX copy request. Exploitation requires a multi-packet sequence to establish ROHC context, commonly in GTP-U or PPP traffic. Wireshark reported no known exploitation in the wild.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitLab issue documented a NULL write and potential heap-corruption condition in Wireshark's ROHC dissector when processing an uncompressed profile with large CID. The flaw required a multi-packet sequence to establish the affected ROHC context and was reported by Arjun Basnet of Securin Labs.
Wireshark published advisory wnpa-sec-2026-51 for a malformed-packet crash vulnerability in the ROHC dissector, affecting versions 4.6.0–4.6.5 and 4.4.0–4.4.15. Fixes were released in versions 4.6.6 and 4.4.16; Wireshark said it was unaware of exploitation in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.