Junglewise Threat Intelligence

CVE-2026-76923: Wireshark Bluetooth HFP heap buffer overflow in AT command parsing

CVE-2026-76923 · Severity: medium · CVSS 5.5 · Published 2026-08-19

Vendors: Wireshark Foundation.

Executive brief

Wireshark is a network analysis tool used by IT professionals and security teams to inspect network traffic. A flaw in its Bluetooth HFP protocol parser allows a specially crafted network packet or capture file to trigger an out-of-bounds memory read, causing Wireshark to crash. An attacker could exploit this to disrupt network monitoring operations or cause denial of service by providing a malicious packet capture file.

Technical details

The Bluetooth HFP Profile dissector in Wireshark's `packet-bthfp.c` contains a heap buffer overflow vulnerability (CWE-125: Out-of-bounds Read) in the parsing of AT command `+XAPL` accessory parameters. The vulnerable code performs fixed four-byte hexadecimal conversions at offsets 0, 5, and 10 within the parameter stream without validating that the parameter is at least 14 bytes long (the expected format is `hhhh-hhhh-hhhh`). A maliciously short AT command like `AT+XAPL=1\r` causes the parser to read beyond the allocated buffer. This can be triggered via a malformed RFCOMM capture file or injected packet. The vulnerability leads to a denial of service crash; Address Sanitizer confirms heap-buffer-overflow conditions. Patches are available in Wireshark 4.6.8 and 4.4.18, which enforce minimum parameter length validation before performing the fixed-offset reads.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17

Timeline

  • 2026-08-12: disclosed
  • 2026-08-19: advisory: CVE-2026-76923 published
  • 2026-08-19: patched: Fixed in Wireshark 4.6.8 and 4.4.18

References