ZeroHour

CVE-2026-76882

PoC mass

Out-of-bounds read in Wireshark Bluetooth ATT dissector causes DoS crash

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

Wireshark contains an out-of-bounds read (CWE-125) in the Bluetooth Attribute Protocol (ATT) dissector, affecting releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. The flaw is triggered when Wireshark dissects malformed or malicious Bluetooth ATT traffic, either from a crafted capture file or during a live Bluetooth capture, causing the application to crash. Because the attack vector is local and requires user interaction, with no confidentiality or integrity impact, the practical consequence is denial of service of the analysis session rather than code execution or data theft. Anyone running the affected 4.6.x or 4.4.x releases who opens untrusted capture files or performs Bluetooth packet capture is exposed. Exploitation is not currently observed in the wild (EPSS ~0.1%, not in CISA KEV), but a public proof-of-concept issue exists in the Wireshark tracker.

What to do: Upgrade Wireshark to a maintenance release later than 4.6.7 on the 4.6 branch or later than 4.4.18 on the 4.4 branch. Until patched, avoid opening untrusted Bluetooth capture files and consider disabling the Bluetooth ATT (btatt) dissector under Analyze > Enabled Protocols, or limit live capture to non-Bluetooth interfaces. Verify the installed version via Help > About Wireshark or 'tshark --version'.

Affected
Wireshark4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
Estimated exposure
massmillions of installations (Wireshark's cumulative downloads are in the hundreds of millions; realistically, users on the affected 4.4.x/4.6.x branches handling… — Wireshark is the de facto standard packet analyzer with hundreds of millions of cumulative downloads across analyst, security, and development workstations, so even the subset running affected 4.4.x/4.6.x maintenance releases and touching…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.