ZeroHour

CVE-2026-76922

PoC mass

Denial-of-service crash in Wireshark Bluetooth BR/EDR FHS dissector

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

Wireshark releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 contain a flaw (CWE-476, null pointer dereference) in the Bluetooth BR/EDR FHS protocol dissector that causes the application to crash. The crash is triggered when Wireshark or TShark dissects a crafted Bluetooth FHS packet, for example when a user opens a malicious capture file or analyzes live Bluetooth BR/EDR traffic. An attacker gains denial of service only: the capture session or analysis run aborts, with no confidentiality or integrity impact and no indication of code execution (CVSS C:N/I:N/A:H, local vector requiring user interaction). Anyone running the affected releases who dissects Bluetooth BR/EDR captures is affected. There is no evidence of in-the-wild exploitation: EPSS is 0.1% (1st percentile), the flaw is not in CISA KEV, and the only public reference is a Wireshark issue-tracker work item.

What to do: Upgrade to a Wireshark release newer than 4.6.7 on the 4.6 branch or newer than 4.4.18 on the 4.4 branch (the latest maintenance release of each branch). Until then, avoid opening untrusted capture files containing Bluetooth BR/EDR traffic, and consider disabling the FHS dissector via Wireshark's Enabled Protocols dialog when analyzing Bluetooth captures. No in-the-wild exploitation is reported, so routine patching cadence is reasonable.

Affected
Wireshark4.6.0 through 4.6.7 and 4.4.0 through 4.4.18
Estimated exposure
massmillions of Wireshark installations run the affected 4.4.x/4.6.x branches, though practical exposure is limited to users dissecting Bluetooth BR/EDR traffic — Wireshark is one of the most widely deployed open-source packet analyzers with an installed base well over a million users, so the current release branches (4.4.x and 4.6.x) plausibly cover millions of installs, but only those processing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-476
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.