Sceawere
Vulnerability Detail
CVE-2026-96422UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Frame Protocol Metadissector Denial-of-Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-617: Reachable Assertion
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:17.077Z",
"pubdate": "2026-09-29T10:17:17.077Z",
"executiveSummary": "A denial-of-service (DoS) vulnerability has been identified within the frame protocol metadissector component of the affected software. This flaw permits an unauthenticated remote attacker to trigger an application crash, resulting in a total loss of availability for the affected service.\nThe vulnerability affects versions 4.4.0 through 4.4.18 and 4.6.0 through 4.6.8. The primary risk implication is the potential for service disruption, as the crash interrupts standard processing threads. Exploitation does not require prior authentication, meaning any network-reachable entity capable of sending malformed protocol data can induce the crash state. There are no known complex prerequisites for exploitation beyond the capability to transmit traffic that the metadissector is configured to parse.\nThis vulnerability is critical for environments where the software acts as a network analyzer or protocol gateway, as the unexpected termination of the process can lead to significant operational downtime and security monitoring gaps.",
"technicalDetails": "The vulnerability originates from improper input validation or boundary handling within the frame protocol metadissector, which is responsible for parsing and dissecting encapsulated frame headers. The root cause lies in the metadissector's failure to safely handle malformed or maliciously crafted data packets that deviate from expected protocol specifications.\nWhen the metadissector processes a specifically crafted packet, it encounters an error condition—likely a memory access violation or an unhandled exception—that the application is unable to recover from gracefully. Given the nature of protocol dissectors, this often occurs during the initial packet parsing phase where field lengths, offset values, or protocol identifiers are validated. If these values are manipulated to exceed expected buffer constraints or point to invalid memory locations, the dissector component triggers an immediate termination to prevent memory corruption or illegal state transitions.\nThe attack flow proceeds as follows: An attacker sends a network packet containing a malformed frame protocol header to the target system. Upon receipt, the network stack passes the data to the affected metadissector component for analysis. As the dissector attempts to map the header fields or allocate memory based on the packet's metadata, it hits the flawed code path. This results in a segmentation fault or similar process-terminating signal. Because the crash occurs within the core dissecting thread, it typically results in the total crash of the parent service or the primary analysis engine.\nThe vulnerability resides within the packet parsing logic of the frame protocol metadissector. Because the parsing is executed at the entry point of data ingestion, the exploit is effective regardless of the user's privilege level, as the dissector processes incoming data in a low-privileged context or before any authentication checks can be applied to the protocol payload itself. Network exposure is high, as the service is inherently designed to listen for and process protocol traffic. There is no requirement for a complex payload beyond ensuring that the protocol fields are malformed in a way that triggers the identified logic flaw within the parser. The impact is strictly confined to service availability; no direct path to arbitrary code execution has been identified, though the crash state confirms that the parser logic is unstable under adversarial conditions."
}