Junglewise Threat Intelligence

CVE-2026-76917: Wireshark Bluetooth AVRCP dissector heap buffer overflow

CVE-2026-76917 · Severity: medium · CVSS 5.5 · Published 2026-08-19

Technologies: Wireshark. Vendors: Wireshark.

Executive brief

Wireshark's Bluetooth AVRCP protocol analyzer contains a heap buffer overflow vulnerability triggered when processing specially crafted Bluetooth capture files or injected packets. An attacker can cause Wireshark to crash or potentially execute code by sending a series of vendor-dependent AVRCP fragments that cause integer overflow during reassembly. This affects users analyzing untrusted network captures or those exposed to malicious Bluetooth traffic.

Technical details

The vulnerability exists in the `dissect_vendor_dependent()` function in `packet-btavrcp.c` (lines 1195–1206), where a uint32_t accumulator tracking fragment payload lengths overflows when reassembling large numbers of fragments (e.g., 65,563 fragments × 65,511 bytes each wraps to ~130 KB). The undersized allocation is then overwritten by a 4 GiB memcpy, corrupting the heap and causing crash (SIGBUS) or potential code execution. The attack requires no user authentication and exploits standard Bluetooth protocol routing (H4→ACL→L2CAP→AVCTP→AVRCP), requiring only an attacker-controlled pcap file or injected Bluetooth packets. Patches are available in Wireshark 4.6.8, 4.4.18, and later.

Affected products

  • Wireshark Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17

Timeline

  • 2026-08-12: disclosed
  • 2026-08-12: patched: Wireshark 4.6.8, 4.4.18

References

Related threats