CVE-2026-96422

Public on 2026-09-29
Modified on 2026-10-01
Description
A syntactically valid pcapng file containing many repeated packet-comment options can abort TShark when it builds the full protocol tree with -V. Wireshark renders every comment before entering the frame dissector's exception boundary. The normal one-million-tree-item safeguard consequently raises an uncaught DissectorError, terminating the process instead of reporting a bounded per-packet dissection error.
The Frame protocol metadissector could crash.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core wireshark Not Affected
Amazon Linux 2023 wireshark Pending Fix
Amazon Linux 2027 Preview wireshark Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H