Wireshark fixed CVE-2026-15173, a heap-buffer-overflow in the pcapng legacy Darwin Process Info Block (DPIB) UUID rewrite path. A malicious pcapng file containing an oversized OPT_DPIB_UUID option can cause Wireshark components to allocate 16 bytes for the UUID but copy the option's actual, larger length during packet-capture rewrite or export operations, resulting in memory corruption and a crash.
The flaw affects Wireshark versions 4.6.0 through 4.6.6 and is remediated in 4.6.7. Researchers reproduced it with 32-byte UUID-option files using editcap and tshark output writing; read-only packet inspection was not reported to trigger the vulnerable path. Wireshark reported no known exploitation as of its advisory and organizations should upgrade systems that process untrusted pcapng captures.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory WNPA-SEC-2026-53 for CVE-2026-15173, a denial-of-service crash issue affecting versions 4.6.0 through 4.6.6. Version 4.6.7 fixed the issue, and Wireshark stated that no exploits were known at the time of the advisory.
Wireshark merged merge request !25404, “wiretap: pcapng-darwin-custom: Don't overflow allocated option size,” and closed issue 21285 with commit 63aab2af. The issue was assigned CVE-2026-15173.
Mitchell Benjamin reported a heap-buffer-overflow in Wireshark's pcapng legacy Darwin Process Info Block UUID rewrite path. A malformed file with an oversized UUID option could trigger the allocation-and-copy mismatch when rewritten or exported through tools such as editcap or tshark.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.