CVE-2021-39920 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file. EPSS estimates a 3.16% chance of exploitation in the next 30 days.

## Description
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

## Metrics
CVSS 3.17.5/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability 3.16%

86.3th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration
- [CWE-476](https://cwe.mitre.org/data/definitions/476.html)

## Affected Software
| Vendor | Product | Versions |
| --- | --- | --- |
| Wireshark | Wireshark | >= 3.4.0, < 3.4.10 |
| Fedoraproject | Fedora | 34 |
| Fedoraproject | Fedora | 35 |

## References
- [Third Party Advisory](https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39920.json)
- [Exploit, Issue Tracking, Third Party Advisory](https://gitlab.com/wireshark/wireshark/-/issues/17705)
- [Third Party Advisory](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6AJFIYIHS3TYDD2EBYBJ5KKE52X34BJ/)
- [Third Party Advisory](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YEWTIRMC2MFQBZ2O5M4CJHJM4JPBHLXH/)
- [Third Party Advisory](https://security.gentoo.org/glsa/202210-04)
- [Third Party Advisory](https://www.debian.org/security/2021/dsa-5019)
- [Vendor Advisory](https://www.wireshark.org/security/wnpa-sec-2021-15.html)

## Timeline
Published Nov 18, 2021
Last Modified Jun 17, 2026
Status Modified

## Frequently Asked Questions
**What is CVE-2021-39920?**  
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

**How severe is CVE-2021-39920?**  
CVE-2021-39920 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 3.16% probability of exploitation in the next 30 days.

**How do I fix CVE-2021-39920?**  
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
