Sceawere

Vulnerability Detail

CVE-2026-96421UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

USB HID Dissector Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-1325: Improperly Controlled Sequential Memory Allocation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:16.930Z",
  "pubdate": "2026-09-29T10:17:16.930Z",
  "executiveSummary": "The USB HID protocol dissector is susceptible to a denial of service vulnerability originating from an infinite loop and memory leak condition.\nThis vulnerability affects product versions 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe flaw allows an unauthenticated attacker to trigger resource exhaustion, specifically impacting system memory availability and process execution continuity.\nSuccessful exploitation results in a persistent denial of service state, effectively crashing the dissector or the host process handling the USB traffic.\nThis vulnerability is particularly critical for systems heavily reliant on USB HID input processing, as it can disrupt hardware-level communication and system stability.\nThe attack flow relies on the ingestion of specially crafted or malformed USB HID packets that violate the expected protocol logic, forcing the dissector into an erroneous execution path.\nNo specific privilege escalation is required to initiate the attack; however, local or physical access to the USB bus or interface is generally implied for traffic injection.",
  "technicalDetails": "The vulnerability resides within the USB HID protocol dissector logic, specifically during the packet parsing and validation phase. The core issue involves a failure in the state machine or loop termination logic when processing malformed USB HID data structures.\nRoot Cause: The dissector fails to properly validate the length or structure fields within incoming HID reports, causing the parser to enter an infinite loop while attempting to interpret non-compliant data. Concurrently, the failure to clear heap-allocated buffers during these aborted or repeated iterations results in a continuous memory leak. This depletion of memory resources, combined with the infinite loop saturating the CPU, causes the target service or application to become unresponsive.\nAttack Flow: 1. The attacker provides a malicious USB HID device or emulates such a device via an interface capable of injecting raw USB traffic. 2. The attacker transmits a specifically crafted sequence of HID report descriptors or data packets. 3. The dissector receives these packets and attempts to process them; the incorrect parsing logic fails to reach an exit condition due to the malformed payload. 4. The process enters an infinite loop, consuming 100% of the assigned CPU core, while subsequent allocation requests within the loop result in sustained memory growth. 5. The host process eventually encounters a process crash due to memory exhaustion or watch-dog timer intervention, resulting in a complete denial of service for the USB subsystem.\nAffected Components: The primary vulnerable component is the USB HID dissector module responsible for packet inspection and protocol normalization. Affected versions include the 4.6.x branch (4.6.0–4.6.8) and the 4.4.x branch (4.4.0–4.4.18).\nPost-Exploitation: The impact is primarily limited to system instability and denial of service. The memory leak ensures that even if the infinite loop is bypassed or interrupted, the residual memory consumption degrades system performance until the process is manually restarted or the system kernel initiates an OOM (Out Of Memory) event. There is no evidence currently suggesting remote code execution via this specific mechanism, though resource exhaustion remains a significant availability risk."
}