ZeroHour

CVE-2026-76923

PoC mass

Out-of-bounds read in Wireshark Bluetooth HFP dissector causes denial of service

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

An out-of-bounds read (CWE-125) in Wireshark's Bluetooth Hands-Free Profile (HFP) dissector can crash the application when it dissects a crafted Bluetooth capture. Because the flaw lives in the dissection path, a denial of service can be triggered by getting an analyst to open a malicious capture file containing HFP traffic, or by feeding such traffic into automated capture-processing pipelines; no data theft or code execution is possible. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected when they process Bluetooth captures. There is no reported exploitation in the wild: the flaw has one public proof-of-concept/issue reference, a very low EPSS score (0.1%, 1st percentile), and is not in CISA KEV. The CVSS 5.5 local/user-interaction vector (AV:L, UI:R, availability-only impact) is consistent with a crash-on-dissection bug.

What to do: Upgrade Wireshark to a release newer than 4.6.7 on the 4.6 branch or newer than 4.4.18 on the 4.4 branch. As interim mitigation, avoid opening untrusted Bluetooth capture files and consider disabling the HFP protocol (Analyze -> Enabled Protocols) or filtering Bluetooth HFP input in automated tshark-based pipelines. Check the Wireshark version on analyst workstations and any hosts that automatically process captures.

Affected
Wireshark4.6.0 to 4.6.7
Wireshark4.4.0 to 4.4.18
Estimated exposure
mass≈1M+ Wireshark installations/users across the two affected release branches, though only Bluetooth HFP traffic actually triggers the crash — Wireshark is one of the most widely deployed packet analyzers (millions of cumulative downloads per release cycle and bundled in many Linux distributions and security toolkits), and the affected ranges span its entire previous branch (4.4)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.