Sceawere

Vulnerability Detail

CVE-2026-95395UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IEEE C37.118 Dissector Memory Leak

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-401: Missing Release of Memory after Effective Lifetime
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:15.900Z",
  "pubdate": "2026-09-29T10:17:15.900Z",
  "executiveSummary": "A memory leak vulnerability exists within the IEEE C37.118 Synchrophasor protocol dissector, impacting specific versions of the affected software. This flaw allows an unauthenticated remote attacker to trigger a denial of service (DoS) condition by exhausting system memory resources. The vulnerability is classified as an improper resource management issue. By repeatedly sending specially crafted protocol packets, an attacker can cause the application to allocate memory that is never subsequently released, eventually leading to process exhaustion or system instability. The vulnerability affects versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18. Due to the nature of protocol dissectors, which often operate in real-time network monitoring or critical infrastructure environments, the impact is significant, potentially leading to the loss of monitoring capabilities or system crashes. No authentication is required for exploitation, making it a viable target for attackers with network access to the target system.",
  "technicalDetails": "The vulnerability resides within the IEEE C37.118 protocol dissector module, which is responsible for parsing and analyzing Synchrophasor data streams in real-time. The root cause is a failure to properly deallocate memory buffers during the dissector's state machine transitions or error-handling routines when processing malformed or specific non-compliant protocol traffic. Specifically, when the dissector encounters certain sequences of IEEE C37.118 data frames, it allocates dynamic memory for internal structure representation or packet reassembly but fails to execute the necessary cleanup operations, such as free() calls, under specific conditions.\nThe attack flow begins with the adversary crafting malicious IEEE C37.118 packets designed to trigger the identified code paths that lead to the memory leak. The attacker sends these packets over the network to the interface monitored by the vulnerable dissector. As the dissector processes these frames, each iteration of the exploit increases the resident set size (RSS) of the application process. Because the dissector is often integrated into high-throughput systems, the attacker can systematically deplete the available heap memory or system RAM by sustaining this traffic.\nExploitation does not require prior authentication or privileged access. The attacker only needs network reachability to the target component. Once the memory pressure reaches a critical threshold, the host system may experience severe performance degradation or the application process will be terminated by the operating system's Out-Of-Memory (OOM) killer. In critical infrastructure environments, this results in the loss of synchrophasor data ingestion, which is vital for wide-area monitoring and protection systems (WAMPAC).\nAffected versions are strictly defined as 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. Post-exploitation, the primary impact is the loss of service availability. There is no evidence of arbitrary code execution; however, the state of the application after the leak renders the dissector unable to perform its primary function. Successful exploitation results in a persistent denial of service that requires manual intervention, such as process or service restarts, to recover operational status."
}
CVE-2026-95395: IEEE C37.118 Dissector Memory Leak (MEDIUM Severity, CVSS: 5.5) | Sceawere