CVE-2026-76923: Out-of-bounds Read in Wireshark
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.6.8
Event History
Frequently Asked Questions
Who is exposed to this denial-of-service issue?
Wireshark installations in the affected 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 version ranges are exposed when processing Bluetooth HFP Profile protocol traffic.
What must an attacker do to trigger the crash?
The attack vector is local and requires user interaction. The provided information indicates that triggering the issue requires Wireshark to process the affected Bluetooth HFP Profile protocol data.
What is the expected impact if exploited?
Successful exploitation can crash Wireshark, causing a denial of service. The supplied CVSS vector indicates no confidentiality or integrity impact.