Bug#1144924: wireshark: CVE-2026-19694 CVE-2026-19695 CVE-2026-19696 CVE-2026-76879 CVE-2026-76880 CVE-2026-76881 CVE-2026-76882 CVE-2026-76883 CVE-2026-76884 CVE-2026-76885 CVE-2026-76886 CVE-2026-76887 CVE-2026-76888 CVE-2026-76889 CVE-2026-76890 CVE-2026-76891 CVE-2026-76917 CVE-2026-76918 CVE-2026-76919 CVE-2026-76920 CVE-2026-76921 CVE-2026-76922 CVE-2026-76923 CVE-2026-76924 CVE-2026-76926 CVE-2026-76927 CVE-2026-76928 CVE-2026-76929

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: wireshark
Version: 4.6.6-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for wireshark.

CVE-2026-19694[0]:
| TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of
| service


CVE-2026-19695[1]:
| Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial
| of service


CVE-2026-19696[2]:
| Ixia IxVeriWave and Vector Informatik BLF file parser crashes in
| 4.6.0 to 4.6.7 allows denial of service on Windows


CVE-2026-76879[3]:
| C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76880[4]:
| RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76881[5]:
| CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76882[6]:
| Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and
| 4.4.0 to 4.4.18 allows denial of service


CVE-2026-76883[7]:
| Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76884[8]:
| ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows
| denial of service


CVE-2026-76885[9]:
| Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76886[10]:
| C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76887[11]:
| Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0
| to 4.4.18 allows denial of service


CVE-2026-76888[12]:
| RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76889[13]:
| UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76890[14]:
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
| of service


CVE-2026-76891[15]:
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
| of service


CVE-2026-76917[16]:
| Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7
| and 4.4.0 to 4.4.18 allows denial of service


CVE-2026-76918[17]:
| SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76919[18]:
| ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76920[19]:
| 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76921[20]:
| CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76922[21]:
| Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and
| 4.4.0 to 4.4.18 allows denial of service


CVE-2026-76923[22]:
| Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and
| 4.4.0 to 4.4.18 allows denial of service


CVE-2026-76924[23]:
| Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76926[24]:
| BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76927[25]:
| H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


CVE-2026-76928[26]:
| X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service


CVE-2026-76929[27]:
| Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19694
    https://www.cve.org/CVERecord?id=CVE-2026-19694
[1] https://security-tracker.debian.org/tracker/CVE-2026-19695
    https://www.cve.org/CVERecord?id=CVE-2026-19695
[2] https://security-tracker.debian.org/tracker/CVE-2026-19696
    https://www.cve.org/CVERecord?id=CVE-2026-19696
[3] https://security-tracker.debian.org/tracker/CVE-2026-76879
    https://www.cve.org/CVERecord?id=CVE-2026-76879
[4] https://security-tracker.debian.org/tracker/CVE-2026-76880
    https://www.cve.org/CVERecord?id=CVE-2026-76880
[5] https://security-tracker.debian.org/tracker/CVE-2026-76881
    https://www.cve.org/CVERecord?id=CVE-2026-76881
[6] https://security-tracker.debian.org/tracker/CVE-2026-76882
    https://www.cve.org/CVERecord?id=CVE-2026-76882
[7] https://security-tracker.debian.org/tracker/CVE-2026-76883
    https://www.cve.org/CVERecord?id=CVE-2026-76883
[8] https://security-tracker.debian.org/tracker/CVE-2026-76884
    https://www.cve.org/CVERecord?id=CVE-2026-76884
[9] https://security-tracker.debian.org/tracker/CVE-2026-76885
    https://www.cve.org/CVERecord?id=CVE-2026-76885
[10] https://security-tracker.debian.org/tracker/CVE-2026-76886
    https://www.cve.org/CVERecord?id=CVE-2026-76886
[11] https://security-tracker.debian.org/tracker/CVE-2026-76887
    https://www.cve.org/CVERecord?id=CVE-2026-76887
[12] https://security-tracker.debian.org/tracker/CVE-2026-76888
    https://www.cve.org/CVERecord?id=CVE-2026-76888
[13] https://security-tracker.debian.org/tracker/CVE-2026-76889
    https://www.cve.org/CVERecord?id=CVE-2026-76889
[14] https://security-tracker.debian.org/tracker/CVE-2026-76890
    https://www.cve.org/CVERecord?id=CVE-2026-76890
[15] https://security-tracker.debian.org/tracker/CVE-2026-76891
    https://www.cve.org/CVERecord?id=CVE-2026-76891
[16] https://security-tracker.debian.org/tracker/CVE-2026-76917
    https://www.cve.org/CVERecord?id=CVE-2026-76917
[17] https://security-tracker.debian.org/tracker/CVE-2026-76918
    https://www.cve.org/CVERecord?id=CVE-2026-76918
[18] https://security-tracker.debian.org/tracker/CVE-2026-76919
    https://www.cve.org/CVERecord?id=CVE-2026-76919
[19] https://security-tracker.debian.org/tracker/CVE-2026-76920
    https://www.cve.org/CVERecord?id=CVE-2026-76920
[20] https://security-tracker.debian.org/tracker/CVE-2026-76921
    https://www.cve.org/CVERecord?id=CVE-2026-76921
[21] https://security-tracker.debian.org/tracker/CVE-2026-76922
    https://www.cve.org/CVERecord?id=CVE-2026-76922
[22] https://security-tracker.debian.org/tracker/CVE-2026-76923
    https://www.cve.org/CVERecord?id=CVE-2026-76923
[23] https://security-tracker.debian.org/tracker/CVE-2026-76924
    https://www.cve.org/CVERecord?id=CVE-2026-76924
[24] https://security-tracker.debian.org/tracker/CVE-2026-76926
    https://www.cve.org/CVERecord?id=CVE-2026-76926
[25] https://security-tracker.debian.org/tracker/CVE-2026-76927
    https://www.cve.org/CVERecord?id=CVE-2026-76927
[26] https://security-tracker.debian.org/tracker/CVE-2026-76928
    https://www.cve.org/CVERecord?id=CVE-2026-76928
[27] https://security-tracker.debian.org/tracker/CVE-2026-76929
    https://www.cve.org/CVERecord?id=CVE-2026-76929

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.