CVE-2026-76882
PoC massOut-of-bounds read in Wireshark Bluetooth ATT dissector causes DoS crash
Wireshark contains an out-of-bounds read (CWE-125) in the Bluetooth Attribute Protocol (ATT) dissector, affecting releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. The flaw is triggered when Wireshark dissects malformed or malicious Bluetooth ATT traffic, either from a crafted capture file or during a live Bluetooth capture, causing the application to crash. Because the attack vector is local and requires user interaction, with no confidentiality or integrity impact, the practical consequence is denial of service of the analysis session rather than code execution or data theft. Anyone running the affected 4.6.x or 4.4.x releases who opens untrusted capture files or performs Bluetooth packet capture is exposed. Exploitation is not currently observed in the wild (EPSS ~0.1%, not in CISA KEV), but a public proof-of-concept issue exists in the Wireshark tracker.
What to do: Upgrade Wireshark to a maintenance release later than 4.6.7 on the 4.6 branch or later than 4.4.18 on the 4.4 branch. Until patched, avoid opening untrusted Bluetooth capture files and consider disabling the Bluetooth ATT (btatt) dissector under Analyze > Enabled Protocols, or limit live capture to non-Bluetooth interfaces. Verify the installed version via Help > About Wireshark or 'tshark --version'.
| Wireshark | 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.