Input validation error in Wireshark - #VU142316
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Bluetooth HFP Profile protocol dissector when parsing malformed packets or packet capture data. A remote attacker can inject a malformed packet onto the wire or trick the victim into opening a crafted packet capture file to cause a denial of service.
User interaction is required when exploitation is performed via a crafted packet capture file.