SharkFest EU 2026 is coming to Brussels! Learn more and register.

wnpa-sec-2026-96 · IEEE C37.118 Synchrophasor protocol dissector memory leak

Summary

Name: IEEE C37.118 Synchrophasor protocol dissector memory leak

Docid: wnpa-sec-2026-96

Date: September 23, 2026

Affected versions: 4.6.0 to 4.6.8, 4.4.0 to 4.4.18

Fixed versions: 4.6.9, 4.4.19

References:

Wireshark issue 21492.
CVE-2026-95395.

Details

Description

The IEEE C37.118 Synchrophasor protocol dissector could leak memory.

Impact

Discovered by Liu Tianzhuo (刘天卓). We are unaware of any exploits for this issue. It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Resolution

Upgrade to Wireshark 4.6.9, 4.4.19 or later.