Sceawere

Vulnerability Detail

CVE-2026-76917UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Bluetooth AVRCP Protocol Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
18h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-122: Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-19T23:16:20.360Z",
  "pubdate": "2026-08-19T23:16:20.360Z",
  "executiveSummary": "A denial of service vulnerability exists within the Bluetooth AVRCP (Audio/Video Remote Control Profile) protocol dissector across specific software versions. The flaw allows an attacker to trigger an application crash, resulting in a denial of service condition on systems processing malicious protocol traffic.\nThe vulnerability directly impacts products utilizing the vulnerable Bluetooth AVRCP protocol dissector implementations, specifically affecting version ranges 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. The risk implication is primarily availability disruption, potentially causing continuous service interruptions or monitoring blindness if the affected software is part of a critical telemetry or communication pipeline.\nAttacker capabilities are limited to causing a denial of service via application termination; remote code execution or data exfiltration is not inherently indicated by this specific crash condition. Exploitation typically requires the capability to transmit or inject specially crafted Bluetooth AVRCP packets into the vulnerable protocol dissector parsing routine.",
  "technicalDetails": "The vulnerability resides in the Bluetooth AVRCP Profile protocol dissector component responsible for parsing incoming packet structures within versions 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18.\nThe root cause stems from improper input validation or memory handling when the dissector encounters malformed, oversized, or unexpected byte sequences within the Bluetooth AVRCP payload fields. When the vulnerable component attempts to traverse or decode the structured protocol data without adequate boundary checks, it triggers a fatal runtime exception, such as a null pointer dereference, buffer over-read, or assertion failure.\nAttack flow begins when an attacker generates a maliciously crafted Bluetooth AVRCP packet designed to exploit parsing logic flaws within the protocol dissector. This packet is transmitted across the applicable communication medium or injected into the packet capture and analysis pipeline where the vulnerable software processes Bluetooth traffic.\nUpon receiving the malicious payload, the affected dissector component parses the input fields sequentially. As it encounters the specifically engineered malformed structures, the parsing logic fails to handle the unexpected data gracefully, resulting in an immediate segmentation fault or unhandled exception.\nThis behavior forces the host process or application containing the dissector to crash abruptly. Because the vulnerability targets the core protocol parsing mechanism, no authentication or high-level privileges are typically required if the underlying interface is exposed to untrusted packet injections, leading directly to a localized or service-wide denial of service."
}
CVE-2026-76917: Bluetooth AVRCP Protocol Denial of Service (MEDIUM Severity, CVSS: 5.5) - Sceawere