Source: wireshark Version: 4.6.6-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for wireshark. CVE-2026-19694[0]: | TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of | service CVE-2026-19695[1]: | Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial | of service CVE-2026-19696[2]: | Ixia IxVeriWave and Vector Informatik BLF file parser crashes in | 4.6.0 to 4.6.7 allows denial of service on Windows CVE-2026-76879[3]: | C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76880[4]: | RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76881[5]: | CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76882[6]: | Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and | 4.4.0 to 4.4.18 allows denial of service CVE-2026-76883[7]: | Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76884[8]: | ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows | denial of service CVE-2026-76885[9]: | Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76886[10]: | C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76887[11]: | Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 | to 4.4.18 allows denial of service CVE-2026-76888[12]: | RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76889[13]: | UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76890[14]: | Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial | of service CVE-2026-76891[15]: | Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial | of service CVE-2026-76917[16]: | Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 | and 4.4.0 to 4.4.18 allows denial of service CVE-2026-76918[17]: | SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76919[18]: | ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76920[19]: | 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76921[20]: | CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76922[21]: | Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and | 4.4.0 to 4.4.18 allows denial of service CVE-2026-76923[22]: | Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and | 4.4.0 to 4.4.18 allows denial of service CVE-2026-76924[23]: | Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76926[24]: | BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76927[25]: | H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service CVE-2026-76928[26]: | X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to | 4.4.18 allows denial of service CVE-2026-76929[27]: | Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 | allows denial of service If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-19694 https://www.cve.org/CVERecord?id=CVE-2026-19694 [1] https://security-tracker.debian.org/tracker/CVE-2026-19695 https://www.cve.org/CVERecord?id=CVE-2026-19695 [2] https://security-tracker.debian.org/tracker/CVE-2026-19696 https://www.cve.org/CVERecord?id=CVE-2026-19696 [3] https://security-tracker.debian.org/tracker/CVE-2026-76879 https://www.cve.org/CVERecord?id=CVE-2026-76879 [4] https://security-tracker.debian.org/tracker/CVE-2026-76880 https://www.cve.org/CVERecord?id=CVE-2026-76880 [5] https://security-tracker.debian.org/tracker/CVE-2026-76881 https://www.cve.org/CVERecord?id=CVE-2026-76881 [6] https://security-tracker.debian.org/tracker/CVE-2026-76882 https://www.cve.org/CVERecord?id=CVE-2026-76882 [7] https://security-tracker.debian.org/tracker/CVE-2026-76883 https://www.cve.org/CVERecord?id=CVE-2026-76883 [8] https://security-tracker.debian.org/tracker/CVE-2026-76884 https://www.cve.org/CVERecord?id=CVE-2026-76884 [9] https://security-tracker.debian.org/tracker/CVE-2026-76885 https://www.cve.org/CVERecord?id=CVE-2026-76885 [10] https://security-tracker.debian.org/tracker/CVE-2026-76886 https://www.cve.org/CVERecord?id=CVE-2026-76886 [11] https://security-tracker.debian.org/tracker/CVE-2026-76887 https://www.cve.org/CVERecord?id=CVE-2026-76887 [12] https://security-tracker.debian.org/tracker/CVE-2026-76888 https://www.cve.org/CVERecord?id=CVE-2026-76888 [13] https://security-tracker.debian.org/tracker/CVE-2026-76889 https://www.cve.org/CVERecord?id=CVE-2026-76889 [14] https://security-tracker.debian.org/tracker/CVE-2026-76890 https://www.cve.org/CVERecord?id=CVE-2026-76890 [15] https://security-tracker.debian.org/tracker/CVE-2026-76891 https://www.cve.org/CVERecord?id=CVE-2026-76891 [16] https://security-tracker.debian.org/tracker/CVE-2026-76917 https://www.cve.org/CVERecord?id=CVE-2026-76917 [17] https://security-tracker.debian.org/tracker/CVE-2026-76918 https://www.cve.org/CVERecord?id=CVE-2026-76918 [18] https://security-tracker.debian.org/tracker/CVE-2026-76919 https://www.cve.org/CVERecord?id=CVE-2026-76919 [19] https://security-tracker.debian.org/tracker/CVE-2026-76920 https://www.cve.org/CVERecord?id=CVE-2026-76920 [20] https://security-tracker.debian.org/tracker/CVE-2026-76921 https://www.cve.org/CVERecord?id=CVE-2026-76921 [21] https://security-tracker.debian.org/tracker/CVE-2026-76922 https://www.cve.org/CVERecord?id=CVE-2026-76922 [22] https://security-tracker.debian.org/tracker/CVE-2026-76923 https://www.cve.org/CVERecord?id=CVE-2026-76923 [23] https://security-tracker.debian.org/tracker/CVE-2026-76924 https://www.cve.org/CVERecord?id=CVE-2026-76924 [24] https://security-tracker.debian.org/tracker/CVE-2026-76926 https://www.cve.org/CVERecord?id=CVE-2026-76926 [25] https://security-tracker.debian.org/tracker/CVE-2026-76927 https://www.cve.org/CVERecord?id=CVE-2026-76927 [26] https://security-tracker.debian.org/tracker/CVE-2026-76928 https://www.cve.org/CVERecord?id=CVE-2026-76928 [27] https://security-tracker.debian.org/tracker/CVE-2026-76929 https://www.cve.org/CVERecord?id=CVE-2026-76929 Regards, Salvatore

