Sceawere
Vulnerability Detail
CVE-2026-96418UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TIFF Dissector Infinite Loop Denial
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:16.500Z",
"pubdate": "2026-09-29T10:17:16.500Z",
"executiveSummary": "A critical vulnerability exists within the TIFF protocol dissector, classified as an infinite loop condition resulting in a Denial of Service (DoS) state.\nThe vulnerability impacts Wireshark versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18, where improper handling of malformed TIFF data triggers an unrecoverable processing loop.\nBy supplying a specially crafted TIFF file or packet stream, an unauthenticated remote attacker can force the dissector into a resource exhaustion state, effectively consuming 100% of the CPU core allocated to the dissector process.\nThis vulnerability poses a significant risk to network analysis infrastructure, as the resulting hang renders the affected software incapable of processing legitimate traffic, leading to monitoring gaps.\nExploitation does not require prior authentication or elevated privileges, provided the attacker can reach the targeted inspection engine with malicious input.",
"technicalDetails": "The vulnerability resides within the logic handling the Tagged Image File Format (TIFF) protocol dissection routines. The root cause is an algorithmic complexity issue where the dissector fails to validate loop termination conditions during the traversal of directory entries or specific image file directories (IFDs) that contain circular references or malformed offset pointers.\nWhen the dissector encounters a maliciously crafted TIFF header or IFD entry, the internal state machine enters a recursive or iterative cycle. The failure to decrement counters or validate pointer boundaries against the input buffer size causes the function to repeatedly process the same memory segments.\nThe attack flow initiates when the target application attempts to dissect a captured packet or file containing the malformed TIFF structure. As the dissector logic iterates through the data, it fails to advance the pointer beyond the corrupted segment, causing the CPU to enter an infinite execution loop.\nBecause the dissection process typically occurs within the main capture thread or a primary inspection thread, this loop causes a complete blockage of the application's event loop. This leads to an immediate loss of service availability for the network monitoring tool.\nAffected versions include 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. The vulnerability is triggered by parsing tainted input, meaning it is accessible to any remote attacker capable of injecting traffic into the network segment or providing a capture file to an analyst using the vulnerable software.\nThere are no requirements for authentication, as the dissector processes incoming data streams at the transport or application layer. Post-exploitation impact is limited to resource exhaustion and service unavailability; however, since the dissector is often used to inspect traffic for security threats, the resulting downtime creates a window where subsequent malicious activity can bypass detection mechanisms."
}