ZOOMSDAY Zoom Annotation CAnnoFormatBlock count1-4 field precisely exceeds 64 causing >128-byte buf1-4 overflow within CAnnoTextFrame/CAnnoTextRange/CAnnoFormatBlock structure (CVE-2026-53413)
Suricata signature detecting a Zoom annotation CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange PDU where a count field (count1-4) precisely exceeds 64, overflowing the 128-byte destination buffer — the wire-level trigger for the ZOOMSDAY buffer overflow, stack overflow, and heap-disclosure primitives (CVE-2026-53413).
Suricata

