CVE-2026-96423

Public on 2026-09-29
Modified on 2026-10-01
Description
The X11 dissector caches, per TCP conversation, one keysym array per keycode in x11_conv_data_t.keycodemap[256]. Each array is allocated in listOfKeysyms() with the keysyms-per-keycode width in force for the message being dissected, but the dissector records only a single scalar state->keysyms_per_keycode, with no per-array width. The X_ChangeKeyboardMapping request writes entries with a request-local width and leaves the scalar untouched; the X_GetKeyboardMapping reply sets the scalar. The two therefore diverge. When a later KeyPress/KeyRelease event is dissected, keycode2keysymString() indexes the cached arrays with the current scalar and never consults each array's real length, so any array allocated narrower than the scalar is read out of bounds. This is reachable from a capture with the default configuration (the X11 dissector is registered on TCP 6000–6063 and enabled by default; no protocol preference or key is required).
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core wireshark Pending Fix
Amazon Linux 2023 wireshark Pending Fix
Amazon Linux 2027 Preview wireshark Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L