CVE-2026-76922: NULL Pointer Dereference in Wireshark
Published Aug 19, 2026
·Updated
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
1 affected component
Wireshark Wireshark>=4.6.0<=4.6.7, >=4.4.0<=4.4.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Aug 19, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this denial-of-service issue?
Users of Wireshark versions 4.6.0 through 4.6.7 or 4.4.0 through 4.4.18 are affected when processing Bluetooth BR/EDR FHS protocol traffic.
2
What does an attacker need to do to trigger the crash?
The attack requires local access and user interaction, according to the CVSS vector. The provided data identifies the affected component as the Bluetooth BR/EDR FHS protocol dissector.
3
What is the impact if exploitation succeeds?
Successful exploitation can cause a denial of service by crashing Wireshark. The supplied CVSS vector indicates no confidentiality or integrity impact.