Impact
Wireshark contains an out–of–bounds read in its Bluetooth HFP Profile protocol dissector that can be triggered by a crafted packet. The vulnerability causes Wireshark to crash, interrupting capture and analysis sessions. The impact is limited to loss of availability of the Wireshark instance, with no direct compromise of data confidentiality or integrity reported.
Affected Systems
Applications built on Wireshark Foundation:Wireshark in versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18 are affected by this flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity. EPSS information is not available and the issue is not listed in CISA’s KEV catalog, suggesting a moderate exploitation likelihood. The most likely attack vector is the delivery of a malicious Bluetooth HFP packet to Wireshark while it is actively dissecting traffic; after the out‑of‑bounds read the application will terminate, causing a denial of service for the user.
OpenCVE Enrichment