CVE-2026-96420

Public on 2026-09-29
Modified on 2026-10-01
Description
Toshiba captures are attacker-controlled text files processed after the handler recognizes the Toshiba banner and a packet marker. While searching for the packet OFFSET line, the parser reads into a fixed stack buffer with file_gets(), then forcibly truncates the current line at byte 16 and accepts it if the prefix equals "OFFSET 0001-0203". It then unconditionally parses the packet length from line+64. file_gets() only writes the bytes read plus one terminating NUL and does not clear the rest of the buffer, so a short line such as "OFFSET 0001-0203\n" leaves line[64] and following bytes containing stale/uninitialized stack contents from previous uses of the buffer. sscanf(line+64, ...) therefore reads data that is not part of the current input line, and if no NUL exists in the remaining stack-buffer region it may continue past the end of the stack object. A malicious capture can reach this path by providing a valid Toshiba header, a valid [No.] record header, and a short OFFSET-prefix line. This is an out-of-bounds/stale stack read in an untrusted file parser and can cause undefined behavior or a crash during file open/read.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core wireshark Pending Fix
Amazon Linux 2023 wireshark Pending Fix
Amazon Linux 2027 Preview wireshark Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H