CVE-2026-76882: Out-of-bounds Read in Wireshark
Published Aug 19, 2026
·Updated
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Bluetooth Attribute Protocol dissector>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which Wireshark releases are affected?
The affected release ranges are 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.
2
What conditions are required for exploitation?
The issue has local attack vector, high attack complexity, no privileges required, and requires user interaction. Successful exploitation can cause a denial of service through a crash in the Bluetooth Attribute Protocol dissector.
3
What is the impact on confidentiality and integrity?
The supplied vector indicates no confidentiality or integrity impact. The stated impact is availability loss from a dissector crash.