CVE-2026-95395
Public on 2026-09-29
Modified on 2026-10-01
Description
The SYNCHROPHASOR dissector (packet-synphasor.c) parses CFG3 configuration frames. The function config_3_frame_fast() reads the num_ph (number of phasors) field from the packet without any upper bound check, then allocates 17.8 MB of memory using wmem_file_scope() per frame. This memory is only freed when the capture file is closed, so sending multiple frames causes memory exhaustion and process termination.
A single 78-byte UDP packet to port 4713 triggers a 17.8 MB allocation. 1000 frames (~200 KB on disk) cause ~17 GB of memory consumption, resulting in OOM kill or g_malloc abort.
A single 78-byte UDP packet to port 4713 triggers a 17.8 MB allocation. 1000 frames (~200 KB on disk) cause ~17 GB of memory consumption, resulting in OOM kill or g_malloc abort.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | wireshark | Not Affected | ||
| Amazon Linux 2023 | wireshark | Pending Fix | ||
| Amazon Linux 2027 Preview | wireshark | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |