CVE-2026-76923
PoC massOut-of-bounds read in Wireshark Bluetooth HFP dissector causes denial of service
An out-of-bounds read (CWE-125) in Wireshark's Bluetooth Hands-Free Profile (HFP) dissector can crash the application when it dissects a crafted Bluetooth capture. Because the flaw lives in the dissection path, a denial of service can be triggered by getting an analyst to open a malicious capture file containing HFP traffic, or by feeding such traffic into automated capture-processing pipelines; no data theft or code execution is possible. Users running Wireshark 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected when they process Bluetooth captures. There is no reported exploitation in the wild: the flaw has one public proof-of-concept/issue reference, a very low EPSS score (0.1%, 1st percentile), and is not in CISA KEV. The CVSS 5.5 local/user-interaction vector (AV:L, UI:R, availability-only impact) is consistent with a crash-on-dissection bug.
What to do: Upgrade Wireshark to a release newer than 4.6.7 on the 4.6 branch or newer than 4.4.18 on the 4.4 branch. As interim mitigation, avoid opening untrusted Bluetooth capture files and consider disabling the HFP protocol (Analyze -> Enabled Protocols) or filtering Bluetooth HFP input in automated tshark-based pipelines. Check the Wireshark version on analyst workstations and any hosts that automatically process captures.
| Wireshark | 4.6.0 to 4.6.7 |
| Wireshark | 4.4.0 to 4.4.18 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.