The vendor explicitly identifies these products as affected by this CVE.
- wireshark as a component of Red Hat Enterprise Linux 10
- wireshark-cli as a component of Red Hat Enterprise Linux 10
- wireshark-devel as a component of Red Hat Enterprise Linux 10
- wireshark.src as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in Wireshark. The Bluetooth Attribute Protocol dissector contains an out-of-bounds read vulnerability. A remote attacker could exploit this by crafting a malicious Bluetooth packet, leading to a crash of the Wireshark application. This crash results in a denial of service (DoS), preventing the user from analyzing network traffic.
- Remediation
- Do not open untrusted packet capture files or capture traffic from untrusted networks with Wireshark.
