[Git][security-tracker-team/security-tracker][master] remaining wireshark issues CVEfied

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 20 12:35:58 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
630fa344 by Moritz Muehlenhoff at 2026-08-20T12:53:42+02:00
remaining wireshark issues CVEfied

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35,7 +35,10 @@ CVE-2026-76922 (Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-80.html
 	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21452
 CVE-2026-76921 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-83.html
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21458
+	NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21457 (private)
 CVE-2026-76920 (3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
 	- wireshark <unfixed>
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-81.html
@@ -45,31 +48,44 @@ CVE-2026-76919 (ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-86.html
 	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21467
 CVE-2026-76918 (SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-85.html
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21465
 CVE-2026-76917 (Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and ...)
 	- wireshark <unfixed>
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-91.html
 	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21488
 CVE-2026-76891 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-64
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21395
 CVE-2026-76890 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-65
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21399
 CVE-2026-76889 (UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
 	- wireshark <unfixed>
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-66
 	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21413
 CVE-2026-76888 (RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-67
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21396
 CVE-2026-76887 (Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 t ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-69.html
 CVE-2026-76886 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18  ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-75.html
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21439
 CVE-2026-76885 (Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.1 ...)
 	- wireshark <unfixed>
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-71.html
 	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21414
 CVE-2026-76884 (ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-72.html
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21415
 CVE-2026-76883 (Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4. ...)
 	- wireshark <unfixed>
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-74.html
@@ -79,9 +95,13 @@ CVE-2026-76882 (Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 a
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-73.html
 	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21424
 CVE-2026-76881 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-76.html
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21446
 CVE-2026-76880 (RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
-	TODO: check
+	- wireshark <unfixed>
+	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-88.html
+	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21478
 CVE-2026-76879 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18  ...)
 	- wireshark <unfixed>
 	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-89.html
@@ -12019,50 +12039,6 @@ CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management comp
 	NOT-FOR-US: Pentestify
 CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student Information ...)
 	NOT-FOR-US: SourceCodester
-CVE-2026-XXXX [wnpa-sec-2026-64 Sharkd utility crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-64
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21395
-CVE-2026-XXXX [wnpa-sec-2026-65 Sharkd utility crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-65
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21399
-CVE-2026-XXXX [wnpa-sec-2026-67 RDP protocol dissector crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-67
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21396
-CVE-2026-XXXX [wnpa-sec-2026-68 TTX Logger file parser crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-68.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21389
-CVE-2026-XXXX [wnpa-sec-2026-69 Dissection engine reassembly crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-69.html
-CVE-2026-XXXX [wnpa-sec-2026-72 ERF file parser crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-72.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21415
-CVE-2026-XXXX [wnpa-sec-2026-75 C12.22 protocol dissector crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-75.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21439
-CVE-2026-XXXX [wnpa-sec-2026-76 CMS protocol dissector crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-76.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21446
-CVE-2026-XXXX [wnpa-sec-2026-83 CMS protocol dissector crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-83.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21458
-	NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21457 (private)
-CVE-2026-XXXX [wnpa-sec-2026-85 SSH protocol dissector crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-85.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21465
-CVE-2026-XXXX [wnpa-sec-2026-88 RRC protocol dissector crash]
-	- wireshark <unfixed>
-	NOTE: https://www.wireshark.org/security/wnpa-sec-2026-88.html
-	NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21478
 CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 ...)
 	- wireshark <unfixed>
 	[trixie] - wireshark <not-affected> (Only affects 4.6)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/630fa3445e97a4eefdb5edec4e9f810a1d696a5f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/630fa3445e97a4eefdb5edec4e9f810a1d696a5f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/29d4d0df/attachment.htm>


More information about the debian-security-tracker-commits mailing list