CVE-2026-6867
Wireshark 4.4.0 – 4.4.14
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HSummary
CVE-2026-6867 is a medium-severity Improperly Controlled Sequential Memory Allocation (CWE-1325) vulnerability in Wireshark Wireshark. Its CVSS base score is 5.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Endpoint Denial of Service (T1499); ranked at the 3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to SC-6 (Resource Availability) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-26346
Vulnerability Data
SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V2.4.1V13.1.2V13.2.6
Mitigating Controls (NIST 800-53 r5) AI
SC-6 directly enforces resource quotas and priority allocations that stop unbounded sequential memory requests from exhausting the system.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require developers to enforce total memory limits during sequential allocations.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect unbounded allocation patterns, but removing the weakness does not fulfill testing obligations.
Secure development life cycle includes resource-management requirements that can prevent uncontrolled per-object allocations.
Secure architecture principles can mandate bounded resource usage, but eliminating this CWE does not address broader architectural controls.
Secure coding standards can require explicit limits on memory per object, yet fixing the weakness alone does not satisfy the full control.
Capacity management directly limits total memory consumption across objects, mitigating unbounded sequential allocations.