Sceawere

Vulnerability Detail

CVE-2026-96422UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Frame Protocol Metadissector Denial-of-Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-617: Reachable Assertion
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T10:17:17.077Z",
  "pubdate": "2026-09-29T10:17:17.077Z",
  "executiveSummary": "A denial-of-service (DoS) vulnerability has been identified within the frame protocol metadissector component of the affected software. This flaw permits an unauthenticated remote attacker to trigger an application crash, resulting in a total loss of availability for the affected service.\nThe vulnerability affects versions 4.4.0 through 4.4.18 and 4.6.0 through 4.6.8. The primary risk implication is the potential for service disruption, as the crash interrupts standard processing threads. Exploitation does not require prior authentication, meaning any network-reachable entity capable of sending malformed protocol data can induce the crash state. There are no known complex prerequisites for exploitation beyond the capability to transmit traffic that the metadissector is configured to parse.\nThis vulnerability is critical for environments where the software acts as a network analyzer or protocol gateway, as the unexpected termination of the process can lead to significant operational downtime and security monitoring gaps.",
  "technicalDetails": "The vulnerability originates from improper input validation or boundary handling within the frame protocol metadissector, which is responsible for parsing and dissecting encapsulated frame headers. The root cause lies in the metadissector's failure to safely handle malformed or maliciously crafted data packets that deviate from expected protocol specifications.\nWhen the metadissector processes a specifically crafted packet, it encounters an error condition—likely a memory access violation or an unhandled exception—that the application is unable to recover from gracefully. Given the nature of protocol dissectors, this often occurs during the initial packet parsing phase where field lengths, offset values, or protocol identifiers are validated. If these values are manipulated to exceed expected buffer constraints or point to invalid memory locations, the dissector component triggers an immediate termination to prevent memory corruption or illegal state transitions.\nThe attack flow proceeds as follows: An attacker sends a network packet containing a malformed frame protocol header to the target system. Upon receipt, the network stack passes the data to the affected metadissector component for analysis. As the dissector attempts to map the header fields or allocate memory based on the packet's metadata, it hits the flawed code path. This results in a segmentation fault or similar process-terminating signal. Because the crash occurs within the core dissecting thread, it typically results in the total crash of the parent service or the primary analysis engine.\nThe vulnerability resides within the packet parsing logic of the frame protocol metadissector. Because the parsing is executed at the entry point of data ingestion, the exploit is effective regardless of the user's privilege level, as the dissector processes incoming data in a low-privileged context or before any authentication checks can be applied to the protocol payload itself. Network exposure is high, as the service is inherently designed to listen for and process protocol traffic. There is no requirement for a complex payload beyond ensuring that the protocol fields are malformed in a way that triggers the identified logic flaw within the parser. The impact is strictly confined to service availability; no direct path to arbitrary code execution has been identified, though the crash state confirms that the parser logic is unstable under adversarial conditions."
}