Sceawere

Vulnerability Detail

CVE-2026-95388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sharkd Denial of Service Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-122: Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:14.867Z",
  "pubdate": "2026-09-29T10:17:14.867Z",
  "executiveSummary": "The Sharkd utility within the Wireshark software suite is susceptible to a denial-of-service (DoS) vulnerability triggered by a software crash.\nThis vulnerability affects versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe flaw stems from an internal handling error within the Sharkd service, which allows a remote or local attacker to induce an abnormal termination of the process.\nSuccessful exploitation results in the immediate unavailability of the Sharkd service, disrupting dependent diagnostic or automated analysis workflows.\nThe risk implication is primarily operational, as the crash disrupts the utility's ability to process requests or analyze packet captures, thereby hindering incident response and network monitoring capabilities.\nExploitation does not inherently require high-level privileges but is contingent on the attacker’s ability to reach and interact with the Sharkd interface to trigger the vulnerable code path.",
  "technicalDetails": "The vulnerability resides in the core operational logic of the Sharkd utility, which acts as a specialized backend service for Wireshark-based operations. Sharkd is designed to provide a JSON-RPC-based interface for programmatic access to Wireshark's packet dissectors and analysis capabilities.\nThe crash condition is triggered when the utility receives input that violates expected data handling constraints or triggers an unhandled exception during packet processing or command execution within the Sharkd binary.\nThe root cause is an improper handling of input data, leading to a memory safety violation or an unhandled logic branch that terminates the process. When Sharkd encounters these specific malformed inputs or sequences, the internal state machine fails, leading to an immediate segmentation fault or process abortion.\nThe attack flow commences when an attacker establishes communication with the Sharkd service port or interface. The attacker then submits a specially crafted request or payload designed to interact with the vulnerable parsing component. Because Sharkd typically runs as a long-lived service, the interaction involves sending a sequence of bytes that the internal parser is unable to normalize correctly.\nUpon processing the malformed data, the utility executes an illegal operation. If the vulnerable function does not include robust exception handling or boundary checking, the runtime environment terminates the utility to prevent further undefined behavior. This behavior causes a service outage, as the process cannot recover gracefully and remains in a crashed state until manually restarted.\nThe affected versions, specifically 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18, indicate a persistent deficiency in how the utility validates input streams against the expected protocol or command schema. The impact is confined to the Sharkd instance itself; however, in environments where Sharkd is leveraged for automated security monitoring, this vulnerability can be used as a deliberate blind-spotting technique. By inducing a persistent DoS, an attacker can prevent the security infrastructure from parsing captured traffic, effectively masking malicious activity that would otherwise be dissected by the utility. Exploitation can occur over a network connection if Sharkd is exposed, or locally if the attacker has access to the machine executing the utility."
}
CVE-2026-95388: Sharkd Denial of Service Vulnerability (MEDIUM Severity, CVSS: 5.5) | Sceawere