Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability (CVE-2026-96417)
CVE number = CVE-2026-96417
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark.
User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of RF4CE key exchange packets.
The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a buffer.
An attacker can leverage this vulnerability to execute code in the context of the current process.
Wireshark has issued an update to correct this vulnerability. More details can be found at:
https://gitlab.com/wireshark/wireshark/-/commit/b2d359a23f9557d1740ded6b5e71ec8eea4b1695

Kerry is a Content Creator at www.systemtek.co.uk she has spent many years working in IT support, her main interests are computing, networking and AI.
