Sceawere
Vulnerability Detail
CVE-2026-95393UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CSN.1 Dissector Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-122: Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-29T10:17:15.610Z",
"pubdate": "2026-09-29T10:17:15.610Z",
"executiveSummary": "A vulnerability exists within the CSN.1 protocol dissector affecting specific versions of the software product. This vulnerability is classified as a Denial of Service (DoS) flaw.\nThe issue arises from improper handling of malformed or unexpected CSN.1 protocol data, which triggers a crash within the dissector component.\nImpact includes the termination of the parsing process, leading to a service disruption. If the dissector is utilized by a critical service, this can result in the complete unavailability of network traffic analysis or protocol handling functionality.\nThe vulnerability is reachable via the network, allowing a remote, unauthenticated attacker to supply a specially crafted packet that triggers the crash.\nNo specific privileges are required to initiate the attack, as the dissector processes incoming data streams directly. Successful exploitation does not lead to remote code execution but forces an immediate application fault.",
"technicalDetails": "The vulnerability resides within the CSN.1 protocol dissector, which is responsible for parsing and translating bit-level protocol definitions into structured formats for analysis. The dissector fails to safely handle non-compliant or malformed input streams, leading to a memory access violation or an unhandled exception.\nRoot Cause: The flaw is rooted in an logic error in the state machine or the bit-field validation routines of the CSN.1 dissector. When an incoming packet contains malformed data or violates the expected structural constraints defined by the CSN.1 specification, the dissector fails to perform bounds checking or type validation correctly, leading to an attempt to access invalid memory or an infinite loop resulting in resource exhaustion.\nAffected Versions: The vulnerability impacts versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nAttack Flow: An attacker performs the exploit by injecting a malicious packet into the network segment monitored or processed by the target application. Because the dissector automatically parses inbound traffic, the malformed CSN.1 structures are processed without prior authentication or privilege verification. Upon encountering the trigger sequence, the dissector component crashes.\nPost-Exploitation: The primary impact is the immediate cessation of the dissector’s functionality. If the software is configured to handle multiple streams, the crash may result in a complete service outage. This requires a manual restart or process recovery mechanism, as the dissector cannot recover from the fault autonomously.\nTechnical Complexity: The exploitation requires knowledge of the target's protocol parsing logic to craft a packet that successfully triggers the crash condition while conforming enough to pass initial structural filters. Because the vulnerability involves a parsing error, it falls into the category of memory-corruption or logic-based instability resulting from input sanitization failures."
}