
PEACH
Un cadre d’isolation des locataires
CVE-2026-96421 is a vulnerability in Wireshark's USB HID protocol dissector that causes an infinite loop and memory leak when parsing crafted USB HID traffic. The CVE is currently in "Reserved" status, indicating it has been assigned but not yet fully published in official vulnerability databases. The affected product is Wireshark, with fixed versions referenced in release notes for Wireshark 4.6.9 and 4.4.19 (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes). The vulnerability was inserted into Feedly's threat intelligence feed on September 23, 2026, with updates through September 29, 2026. No CVSS score has been publicly assigned at this time due to the reserved status of the CVE.
The root cause of CVE-2026-96421 is improper handling of crafted USB HID protocol traffic within Wireshark's dissector, leading to an infinite loop condition and associated memory leak (consistent with CWE-835: Loop with Unreachable Exit Condition, and CWE-401: Missing Release of Memory after Effective Lifetime). An attacker can trigger this vulnerability by supplying a specially crafted USB HID capture file or live traffic stream that causes the dissector to enter an unending processing loop, exhausting system memory over time. Exploitation requires the victim to open a malicious capture file or capture live traffic containing the crafted packets (Wireshark 4.6.9 Release Notes, Wireshark Announce).
Successful exploitation of this vulnerability results in a denial-of-service condition on the affected Wireshark instance, as the infinite loop consumes CPU resources and the memory leak progressively exhausts available system memory. This can cause Wireshark to become unresponsive or crash, disrupting network analysis workflows. The impact is limited to availability; there is no evidence of code execution, privilege escalation, or data exfiltration associated with this vulnerability (Wireshark 4.6.9 Release Notes, Cyber Updates).
There are no known public proof-of-concept exploits, exploit kits, or reports of in-the-wild exploitation for CVE-2026-96421 at this time. The Feedly threat intelligence data shows no recorded exploitation events and no PoC entries. Exploitation requires an attacker to either convince a user to open a malicious capture file or position themselves to inject crafted USB HID traffic into a capture session, limiting the practical attack surface. No EPSS score or CISA KEV catalog listing has been identified for this CVE (Wireshark Announce).
.pcap or .pcapng file containing malformed USB HID protocol packets designed to trigger the infinite loop in Wireshark's USB HID dissector.wireshark, tshark, or dumpcap) consuming 100% CPU for an extended period without completing dissection of a capture file..pcap/.pcapng files containing USB HID traffic in user download or temp directories./var/log/syslog, Windows Event Viewer) recording application crashes or OOM events associated with the Wireshark process.Users should upgrade Wireshark to version 4.6.9 or 4.4.19 (or later), which address this vulnerability along with other security fixes (Wireshark 4.6.9 Release Notes, Wireshark 4.4.19 Release Notes). As a workaround prior to patching, users can disable the USB HID protocol dissector within Wireshark's preferences to prevent parsing of USB HID traffic. Users should also exercise caution when opening capture files from untrusted sources.
Heise reported on security vulnerabilities in Wireshark around the time of the patch release, noting that profile import functionality could carry malware in addition to the dissector vulnerabilities (Heise). Cyber Updates 365 covered the Wireshark 4.6.9 release as fixing 19 vulnerabilities, indicating broad community awareness of the patch batch (Cyber Updates). No notable individual researcher commentary or significant social media discussion specific to CVE-2026-96421 has been identified.
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bionic (esm-apps)
wireshark
devel
wireshark
focal (esm-apps)
wireshark
jammy
wireshark
jammy (esm-apps)
wireshark
noble
wireshark
noble (esm-apps)
wireshark
resolute
wireshark
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."