Skip to main content
Vulnerability Database/CVE-2026-95391

CVE-2026-95391: ZigBee ZCL Protocol DoS Vulnerability

CVE-2026-95391 is a denial of service vulnerability in the ZigBee ZCL protocol dissector affecting versions 4.6.0 to 4.6.8. Attackers can crash the dissector to disrupt service. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-95391 Overview

CVE-2026-95391 is a use-after-free vulnerability [CWE-416] in the Wireshark ZigBee Cluster Library (ZCL) protocol dissector. The flaw affects Wireshark versions 4.6.0 through 4.6.8 and can be triggered when the dissector parses a crafted ZigBee packet. Successful exploitation crashes the Wireshark process, producing a denial of service condition against the analyst workstation.

Attackers exploit the issue locally by convincing a user to open a malicious capture file or by injecting crafted traffic into a live capture. The vulnerability affects availability only; confidentiality and integrity are not impacted.

Critical Impact

A malicious capture file or packet stream crashes Wireshark, interrupting incident response and network forensics workflows.

Affected Products

  • Wireshark 4.6.0
  • Wireshark 4.6.x through 4.6.8
  • ZigBee ZCL protocol dissector component

Discovery Timeline

  • 2026-09-29 - CVE-2026-95391 published to the National Vulnerability Database
  • 2026-09-29 - Last updated in NVD database

Technical Details for CVE-2026-95391

Vulnerability Analysis

The vulnerability resides in the ZigBee Cluster Library dissector within Wireshark. ZCL is an application-layer specification used by ZigBee devices to expose functional clusters such as on/off control, metering, and lighting. Wireshark parses ZCL frames to render human-readable protocol trees during packet analysis.

The dissector mishandles memory references while decoding certain ZCL fields, leading to a use-after-free condition. When the parser accesses freed memory during protocol tree construction, the process state becomes inconsistent and Wireshark terminates. The bug is reachable through any capture path that feeds ZigBee traffic to the dissector, including live captures on ZigBee-capable interfaces and offline analysis of .pcap or .pcapng files.

Refer to the Wireshark Security Advisory WNPA-SEC-2026-92 and the GitLab Merge Request for Wireshark for the upstream fix and dissector context.

Root Cause

The root cause is improper lifetime management of a heap-allocated object inside the ZCL dissector. The dissector retains a pointer to memory after it has been released, then dereferences that pointer during subsequent field decoding. The CWE-416 classification captures this use-after-free pattern.

Attack Vector

Exploitation requires local access and user interaction. An attacker delivers a crafted ZigBee packet, typically embedded in a capture file shared with an analyst, or injects the packet into a monitored network segment where Wireshark is actively capturing. Opening the file or processing the live packet triggers the crash. No privileges are required on the target host beyond those of the Wireshark user.

The vulnerability does not yield code execution or data disclosure based on the current advisory. Impact is limited to process termination and loss of in-progress analysis state.

Detection Methods for CVE-2026-95391

Indicators of Compromise

  • Unexpected Wireshark or tshark process crashes shortly after opening a capture file containing ZigBee traffic
  • Capture files received from untrusted sources containing ZCL frames with malformed cluster or attribute fields
  • Repeated dissector faults logged when processing packets on interfaces monitoring ZigBee 802.15.4 traffic

Detection Strategies

  • Inventory analyst workstations running Wireshark 4.6.0 through 4.6.8 and flag them for patching
  • Hash-check any shared capture files against known-bad samples referenced in the Wireshark advisory
  • Monitor endpoint telemetry for wireshark.exe or tshark process exits with abnormal termination codes

Monitoring Recommendations

  • Enable crash reporting on analyst systems to capture stack traces from dissector faults
  • Alert on capture files delivered via email or chat that contain ZigBee protocol data
  • Track Wireshark version distribution across the organization through software asset management

How to Mitigate CVE-2026-95391

Immediate Actions Required

  • Upgrade Wireshark to a fixed release published after version 4.6.8 as identified in WNPA-SEC-2026-92
  • Restrict opening of untrusted capture files on production analyst workstations
  • Disable the ZigBee ZCL dissector on hosts that cannot be patched immediately

Patch Information

The Wireshark project addressed the vulnerability through the merge request tracked at GitLab Merge Request 26096. Administrators should install the fixed Wireshark package from the official distribution channel appropriate for each operating system.

Workarounds

  • Disable the ZigBee ZCL dissector using Analyze > Enabled Protocols and unchecking zbee_zcl
  • Process suspicious capture files inside an isolated virtual machine used only for triage
  • Use tshark with the --disable-protocol zbee_zcl flag when batch-processing untrusted captures
bash
# Disable the ZigBee ZCL dissector when processing untrusted captures
tshark -r suspicious.pcapng --disable-protocol zbee_zcl

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.