CVE-2026-96420
Received Received - Intake

Toshiba File Parser Crash Leads to DoS

Vulnerability report for CVE-2026-96420, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitLab Inc.

Description

Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
toshiba file_parser From 4.4.0 (inc) to 4.4.18 (inc)
toshiba file_parser From 4.6.0 (inc) to 4.6.8 (inc)
wireshark wireshark From 4.4.0 (inc) to 4.6.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-96420 is a vulnerability in Wireshark's Toshiba file parser that causes a crash leading to denial of service. It affects versions 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18. The issue occurs when processing a malformed packet trace file, specifically a short OFFSET line in the Toshiba capture file format. The parser reads into a fixed stack buffer without clearing it, causing unintended data reads that may crash Wireshark.

Detection Guidance

To detect this vulnerability, monitor for crashes in Wireshark when opening Toshiba capture files. Check Wireshark version with 'wireshark --version' to see if it falls within vulnerable ranges (4.6.0-4.6.8 or 4.4.0-4.4.18). Inspect network traffic for unusual Toshiba file parser activity or malformed packets.

Impact Analysis

If exploited, this vulnerability could allow an attacker to crash Wireshark by convincing a user to open a specially crafted Toshiba capture file. This results in denial of service, disrupting network analysis and monitoring activities. No known exploits exist currently, but users should upgrade to patched versions to avoid potential risks.

Compliance Impact

This vulnerability causes a denial of service through a crash in Wireshark's Toshiba file parser. While it does not directly expose or leak data, a crash could disrupt monitoring or logging activities, potentially impacting compliance with standards requiring continuous availability of systems handling sensitive data like GDPR or HIPAA.

Mitigation Strategies

Upgrade Wireshark to version 4.6.9 or 4.4.19 or later immediately. Avoid opening untrusted Toshiba capture files. If upgrading is not possible, disable the Toshiba file parser in Wireshark's preferences or avoid using affected versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96420. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart