CVE-2018-16056: Wireshark Vulnerability — Fix & Details
CVE-2018-16056
CVE-2018-16056 is a vulnerability of currently unknown severity. In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists. EPSS estimates a 3.35% chance of exploitation in the next 30 days.
Description
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.
Metrics
- EPSS Probability: 3.35%
- 87.2th percentile
Probability of exploitation in the next 30 days. Learn more
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wireshark | Wireshark | >= 2.2.0, <= 2.2.16 |
| Wireshark | Wireshark | >= 2.4.0, <= 2.4.8 |
| Wireshark | Wireshark | >= 2.6.0, <= 2.6.2 |
| Debian | Debian Linux | 9.0 |
References
- OpenSUSE Security Announcement
- SecurityFocus Advisory Third Party Advisory, VDB Entry
- SecurityTracker Advisory Third Party Advisory, VDB Entry
- Wireshark Bugzilla Issue Issue Tracking
- Wireshark Review Commit
- Debian Security Advisory Third Party Advisory
- Wireshark Vendor Advisory Vendor Advisory
Timeline
- Published: Aug 30, 2018
- Last Modified: Jun 17, 2026
- Status: Modified
Frequently Asked Questions
What is CVE-2018-16056?
How severe is CVE-2018-16056?
Severity scoring for CVE-2018-16056 is pending analysis. The EPSS model estimates a 3.35% probability of exploitation in the next 30 days.
How do I fix CVE-2018-16056?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Related CVEs from 2018
- CVE-2018-16048 An issue was discovered in GitLab Community and Enterprise Edition.
- CVE-2018-16049 An issue was discovered in GitLab Community and Enterprise Edition.
- CVE-2018-1605 IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0.
- CVE-2018-16050 An issue was discovered in GitLab Community and Enterprise Edition.
- CVE-2018-16051 An issue was discovered in GitLab Community and Enterprise Edition.
- CVE-2018-16055 An authenticated command injection vulnerability exists.
- CVE-2018-16057 In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16.
- CVE-2018-16058 In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16.
- CVE-2018-16059 Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices.
- CVE-2018-1606 IBM Jazz based applications.
- CVE-2018-16060 Mitsubishi Electric Europe B.V. SmartRTU devices.
- CVE-2018-16061 Mitsubishi Electric Europe B.V. SmartRTU devices.