CVE-2026-76917
PoC massHeap buffer overflow in Wireshark Bluetooth AVRCP dissector causes DoS crash
Wireshark versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a heap-based buffer overflow (CWE-122) in the Bluetooth AVRCP (Audio/Video Remote Control Profile) protocol dissector that causes a dissector crash, leading to denial of service. The flaw is triggered when Wireshark or tshark dissects a malformed or maliciously crafted AVRCP packet, which can occur during a live Bluetooth capture or when a user opens a crafted packet-capture file, consistent with the CVSS vector (local attack, user interaction required). An attacker who induces a user to open a malicious capture or analyze hostile Bluetooth traffic gains a crash of the analysis session (high availability impact), with no confidentiality or integrity impact. Anyone running the affected releases on desktops, servers, or automated tshark-based pipelines is affected, though practical exposure is largely limited to users handling Bluetooth captures or untrusted pcap files. No exploitation in the wild is reported (0.1% EPSS, not in CISA KEV), and one public proof-of-concept issue is available on the Wireshark GitLab tracker.
What to do: Upgrade Wireshark to a release newer than the affected ranges — a 4.6.x build later than 4.6.7 or a 4.4.x build later than 4.4.18 — as tracked in the vendor's advisory and issue 21488. Until patched, avoid opening untrusted capture files and avoid live Bluetooth captures in affected versions, and audit any tshark-based automation that processes untrusted pcaps for crash exposure.
| wireshark | 4.6.0 through 4.6.7 |
| wireshark | 4.4.0 through 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.