CVE-2026-96421

Public on 2026-09-29
Modified on 2026-10-01
Description
The USB HID dissector reconstructs a device's HID report descriptor from a GET DESCRIPTOR control-transfer response and parses it in parse_report_descriptor(). When the descriptor declares a Usage Minimum / Usage Maximum pair, the dissector expands the inclusive range into a wmem array with for (uint32_t j = usage_min; j <= usage_max; j++). Both bounds come straight from the capture, and HID "extended usage" items carry a full 4-byte usage value, so usage_max can be 0xFFFFFFFF. At that point j++ wraps 0xFFFFFFFF -> 0, the j <= usage_max test is unconditionally true, and the loop never terminates while appending 4 bytes per iteration to a file-scoped wmem array — an infinite loop that also grows the heap without bound.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core wireshark Not Affected
Amazon Linux 2023 wireshark Pending Fix
Amazon Linux 2027 Preview wireshark Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H