Sceawere
Vulnerability Detail
CVE-2026-96423UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
X11 Protocol Dissector Denial-of-Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-122: Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T10:17:17.220Z",
"pubdate": "2026-09-29T10:17:17.220Z",
"executiveSummary": "A denial-of-service (DoS) vulnerability has been identified within the X11 protocol dissector. This flaw allows an unauthenticated, remote attacker to crash the affected application by sending a specifically crafted X11 packet.\nThe vulnerability affects versions 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. The dissector fails to properly validate incoming protocol data, leading to an abnormal termination of the process when parsing malicious input.\nThe primary impact is the complete service interruption of the vulnerable component, preventing legitimate users from accessing services reliant on the dissector. No authentication or elevated privileges are required for an attacker to initiate this crash, significantly lowering the barrier for exploitation. This represents a high-availability risk, as the service becomes unreachable until a manual or automated restart occurs. Organizations should prioritize updating to a patched version once available to mitigate potential service outages.",
"technicalDetails": "The vulnerability resides within the X11 protocol dissector logic, responsible for parsing and analyzing the structure of X11 traffic. The root cause is a failure in bounds checking or state validation during the deserialization or processing of malformed protocol fields within the X11 stream.\nWhen the dissector encounters a packet containing unexpected length fields, recursive depth values, or invalid header structures, it enters an undefined state or triggers an exception that the application code fails to handle gracefully. This results in a crash, often manifesting as a segmentation fault or an unhandled memory access error within the dissector component.\nThe exploitation flow begins when an attacker directs a crafted X11 stream towards the network service or application utilizing the vulnerable dissector. The attacker does not need to establish a legitimate X11 session; sending the malformed packet to the relevant port or interface is sufficient to trigger the parsing logic. Once the dissector reads the payload, it attempts to traverse the malicious data structures. During this process, the dissector reaches an invalid pointer or memory location, causing the process to terminate.\nBecause the X11 dissector is typically a foundational component in packet analysis tools, network monitoring systems, or remote display gateways, the impact of the crash is immediate and often propagates to the entire application. The vulnerability is characterized as a memory safety or logic error in the handling of external input. Because the dissector processes input from the wire, the attack surface is exposed to any entity capable of sending traffic to the target system. Exploitation requires no prior knowledge of the target's internal state, as the crash is triggered by the dissector's standard behavior of processing incoming data. Post-exploitation, the service remains in a failed state, resulting in a permanent denial of service for all users dependent on the dissector's functionality until the process is manually restarted."
}