Sceawere

Vulnerability Detail

CVE-2026-95386UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TTL Parser Infinite Loop DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:14.560Z",
  "pubdate": "2026-09-29T10:17:14.560Z",
  "executiveSummary": "A critical denial-of-service (DoS) vulnerability has been identified in the TTL file parsing component within versions 4.6.0 through 4.6.8.\nThe flaw stems from an improper handling of input data, which triggers an infinite loop during the parsing process.\nSuccessful exploitation allows an unauthenticated, remote attacker to consume 100% of the CPU resources assigned to the affected process, effectively causing a service hang or crash.\nThe vulnerability poses a high risk to availability, as it can be triggered by submitting a specifically crafted TTL file.\nThe affected product requires immediate attention to ensure service continuity, as the vulnerability resides in the core logic responsible for interpreting TTL data structures.\nNo user interaction or elevated privileges are required to initiate the attack, provided the parser is exposed to untrusted file inputs.",
  "technicalDetails": "The vulnerability originates in the TTL file parsing logic, where the state machine responsible for processing incoming data fails to correctly handle malformed or maliciously crafted sequence structures.\nWhen the parser encounters a specific, unexpected input pattern, the internal logic enters an infinite loop. This state is reached because the parsing function fails to increment its data pointer or validate terminal conditions within the loop iteration logic.\nThe affected component is the internal TTL parser routine. During standard operation, the parser iterates through the input stream, transforming TTL data into internal memory structures. When the parser is presented with the malicious payload, the loop condition remains constantly true, causing the process to enter a busy-wait state.\nThe exploit flow begins when a user uploads or references a crafted TTL file. Once the application attempts to process the file, the parser reads the input stream and enters the infinite loop. Because this loop occurs within the primary thread handling the file ingestion, the application becomes unresponsive, resulting in a complete denial of service.\nThe vulnerability affects versions 4.6.0 through 4.6.8. Exploitation does not require authentication or elevated privileges, as the parser is typically invoked upon the receipt or loading of a TTL file. If the parsing interface is network-exposed, an attacker can trigger the crash remotely by submitting the payload via the supported file upload or ingestion mechanism.\nThe primary impact of this vulnerability is total system resource exhaustion. The affected process will consume maximum CPU cycles, preventing other operations from being scheduled by the operating system kernel. This state will persist until the process is manually terminated by an administrator or the service crashes due to watchdog timeout mechanisms. There is no evidence suggesting that this vulnerability facilitates arbitrary code execution; however, the resulting service unavailability constitutes a significant security risk for environments relying on continuous TTL data processing."
}
CVE-2026-95386: TTL Parser Infinite Loop DoS (MEDIUM Severity, CVSS: 5.5) | Sceawere