ZeroHour

CVE-2026-76917

PoC mass

Heap buffer overflow in Wireshark Bluetooth AVRCP dissector causes DoS crash

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a heap-based buffer overflow (CWE-122) in the Bluetooth AVRCP (Audio/Video Remote Control Profile) protocol dissector that causes a dissector crash, leading to denial of service. The flaw is triggered when Wireshark or tshark dissects a malformed or maliciously crafted AVRCP packet, which can occur during a live Bluetooth capture or when a user opens a crafted packet-capture file, consistent with the CVSS vector (local attack, user interaction required). An attacker who induces a user to open a malicious capture or analyze hostile Bluetooth traffic gains a crash of the analysis session (high availability impact), with no confidentiality or integrity impact. Anyone running the affected releases on desktops, servers, or automated tshark-based pipelines is affected, though practical exposure is largely limited to users handling Bluetooth captures or untrusted pcap files. No exploitation in the wild is reported (0.1% EPSS, not in CISA KEV), and one public proof-of-concept issue is available on the Wireshark GitLab tracker.

What to do: Upgrade Wireshark to a release newer than the affected ranges — a 4.6.x build later than 4.6.7 or a 4.4.x build later than 4.4.18 — as tracked in the vendor's advisory and issue 21488. Until patched, avoid opening untrusted capture files and avoid live Bluetooth captures in affected versions, and audit any tshark-based automation that processes untrusted pcaps for crash exposure.

Affected
wireshark4.6.0 through 4.6.7
wireshark4.4.0 through 4.4.18
Estimated exposure
massmillions of desktop/toolchain installs on affected branches (estimate), with practical exposure limited to users dissecting Bluetooth/AVRCP traffic or opening… — Wireshark is the de facto open-source packet analyzer with a multi-million-download install base across analyst desktops and automated tshark pipelines, so installs on the affected 4.4.x/4.6.x branches are plausibly in the millions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.