SharkFest EU 2026 is coming to Brussels! Learn more and register.

wnpa-sec-2026-94 · TTL file parser infinite loop

Summary

Name: TTL file parser infinite loop

Docid: wnpa-sec-2026-94

Date: September 23, 2026

Affected versions: 4.6.0 to 4.6.8

Fixed versions: 4.6.9

References:

Wireshark issue 21501.
CVE-2026-95386.

Details

Description

The TTL file parser could go into an infinite loop.

Impact

Discovered independently by Aisle Research (Dmitrijs Trizna, Luigino Camastra, Ze Sheng (O2Lab & TAMU), Igor Morgenstern) and Daniel Birtwhistle. We are unaware of any exploits for this issue. It may be possible to make Wireshark consume excessive CPU resources by convincing someone to read a malformed packet trace file.

Resolution

Upgrade to Wireshark 4.6.9 or later.