CVE-2026-96420
Public on 2026-09-29
Modified on 2026-10-01
Description
Toshiba captures are attacker-controlled text files processed after the handler recognizes the Toshiba banner and a packet marker. While searching for the packet OFFSET line, the parser reads into a fixed stack buffer with file_gets(), then forcibly truncates the current line at byte 16 and accepts it if the prefix equals "OFFSET 0001-0203". It then unconditionally parses the packet length from line+64. file_gets() only writes the bytes read plus one terminating NUL and does not clear the rest of the buffer, so a short line such as "OFFSET 0001-0203\n" leaves line[64] and following bytes containing stale/uninitialized stack contents from previous uses of the buffer. sscanf(line+64, ...) therefore reads data that is not part of the current input line, and if no NUL exists in the remaining stack-buffer region it may continue past the end of the stack object. A malicious capture can reach this path by providing a valid Toshiba header, a valid [No.] record header, and a short OFFSET-prefix line. This is an out-of-bounds/stale stack read in an untrusted file parser and can cause undefined behavior or a crash during file open/read.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | wireshark | Pending Fix | ||
| Amazon Linux 2023 | wireshark | Pending Fix | ||
| Amazon Linux 2027 Preview | wireshark | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |