Sceawere
Vulnerability Detail
CVE-2026-95388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Sharkd Denial of Service Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-122: Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:14.867Z",
"pubdate": "2026-09-29T10:17:14.867Z",
"executiveSummary": "The Sharkd utility within the Wireshark software suite is susceptible to a denial-of-service (DoS) vulnerability triggered by a software crash.\nThis vulnerability affects versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe flaw stems from an internal handling error within the Sharkd service, which allows a remote or local attacker to induce an abnormal termination of the process.\nSuccessful exploitation results in the immediate unavailability of the Sharkd service, disrupting dependent diagnostic or automated analysis workflows.\nThe risk implication is primarily operational, as the crash disrupts the utility's ability to process requests or analyze packet captures, thereby hindering incident response and network monitoring capabilities.\nExploitation does not inherently require high-level privileges but is contingent on the attacker’s ability to reach and interact with the Sharkd interface to trigger the vulnerable code path.",
"technicalDetails": "The vulnerability resides in the core operational logic of the Sharkd utility, which acts as a specialized backend service for Wireshark-based operations. Sharkd is designed to provide a JSON-RPC-based interface for programmatic access to Wireshark's packet dissectors and analysis capabilities.\nThe crash condition is triggered when the utility receives input that violates expected data handling constraints or triggers an unhandled exception during packet processing or command execution within the Sharkd binary.\nThe root cause is an improper handling of input data, leading to a memory safety violation or an unhandled logic branch that terminates the process. When Sharkd encounters these specific malformed inputs or sequences, the internal state machine fails, leading to an immediate segmentation fault or process abortion.\nThe attack flow commences when an attacker establishes communication with the Sharkd service port or interface. The attacker then submits a specially crafted request or payload designed to interact with the vulnerable parsing component. Because Sharkd typically runs as a long-lived service, the interaction involves sending a sequence of bytes that the internal parser is unable to normalize correctly.\nUpon processing the malformed data, the utility executes an illegal operation. If the vulnerable function does not include robust exception handling or boundary checking, the runtime environment terminates the utility to prevent further undefined behavior. This behavior causes a service outage, as the process cannot recover gracefully and remains in a crashed state until manually restarted.\nThe affected versions, specifically 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18, indicate a persistent deficiency in how the utility validates input streams against the expected protocol or command schema. The impact is confined to the Sharkd instance itself; however, in environments where Sharkd is leveraged for automated security monitoring, this vulnerability can be used as a deliberate blind-spotting technique. By inducing a persistent DoS, an attacker can prevent the security infrastructure from parsing captured traffic, effectively masking malicious activity that would otherwise be dissected by the utility. Exploitation can occur over a network connection if Sharkd is exposed, or locally if the attacker has access to the machine executing the utility."
}