CVE-2026-96423
Public on 2026-09-29
Modified on 2026-10-01
Description
The X11 dissector caches, per TCP conversation, one keysym array per keycode in x11_conv_data_t.keycodemap[256]. Each array is allocated in listOfKeysyms() with the keysyms-per-keycode width in force for the message being dissected, but the dissector records only a single scalar state->keysyms_per_keycode, with no per-array width. The X_ChangeKeyboardMapping request writes entries with a request-local width and leaves the scalar untouched; the X_GetKeyboardMapping reply sets the scalar. The two therefore diverge. When a later KeyPress/KeyRelease event is dissected, keycode2keysymString() indexes the cached arrays with the current scalar and never consults each array's real length, so any array allocated narrower than the scalar is read out of bounds. This is reachable from a capture with the default configuration (the X11 dissector is registered on TCP 6000–6063 and enabled by default; no protocol preference or key is required).
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | wireshark | Pending Fix | ||
| Amazon Linux 2023 | wireshark | Pending Fix | ||
| Amazon Linux 2027 Preview | wireshark | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |