Executive brief
Wireshark, a widely-used network protocol analyzer, contains a vulnerability in its Bluetooth Attribute Protocol dissector that can be triggered by processing a specially crafted packet or capture file. An attacker can craft a malicious Bluetooth packet to cause the dissector to read beyond allocated memory boundaries, crashing Wireshark and disrupting network analysis operations.
Technical details
The vulnerability is a heap out-of-bounds (OOB) read in the Bluetooth ATT (Attribute Protocol) dissector (packet-btatt.c:11504) when handling Read Multiple Variable Response packets (opcode 0x21). The dissector indexes a handle[] array without proper bounds checking, allowing a response with more tuples than the paired request contains to read past the allocated buffer. An attacker can exploit this by sending a malformed ATT response packet over Bluetooth or embedding it in a capture file; no authentication is required. The impact is a denial of service via application crash. Patches are available in Wireshark 4.6.8 and 4.4.18.
Affected products
- Wireshark Foundation Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17
Timeline
- 2026-08-12: disclosed
- 2026-08-19: patched: Fixed in versions 4.6.8, 4.4.18