CVE-2026-95387
HIGHCVE-2026-95387 is a high-severity (CVSS 8.1) : Heap-based Buffer Overflow vulnerability. No vendor fix is recorded yet; mitigation options are listed below.
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Description
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2026-95387 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
Disable the SPDY protocol dissector in Wireshark or TShark to prevent processing of the vulnerable protocol format. For TShark command-line usage, pass the protocol disable flag: ``` tshark --disable-protocol spdy -r <capture_file> ``` For persistent configuration across sessions, append the protocol to the disabled protocols file: ``` echo "spdy" >> ~/.config/wireshark/disabled_protos ``` In the Wireshark graphical interface: 1. Navigate to Analyze -> Enabled Protocols... 2. Search for "SPDY" and clear the checkbox. 3. Click OK or Save. Caveat: Disabling the dissector prevents the decoding and inspection of SPDY protocol streams, treating them as generic TCP or TLS payload. Wireshark must…Source: Red Hat security advisory for CVE-2026-95387 (CC BY 4.0)
Frequently Asked Questions
Is CVE-2026-95387 in your dependencies?
Find it across , including transitive dependencies.