# CVE-2018-16056

CVE-2018-16056 is a vulnerability of currently unknown severity. In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists. EPSS estimates a 3.35% chance of exploitation in the next 30 days.

## Description

In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.

## Metrics

- **EPSS Probability**: 3.35% 
- **87.2th percentile**

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Affected Software

| Vendor   | Product     | Versions                |
|----------|-------------|-------------------------|
| Wireshark| Wireshark   | >= 2.2.0, <= 2.2.16     |
| Wireshark| Wireshark   | >= 2.4.0, <= 2.4.8      |
| Wireshark| Wireshark   | >= 2.6.0, <= 2.6.2     |
| Debian   | Debian Linux| 9.0                     |

## References

- [OpenSUSE Security Announcement](https://lists.opensuse.org/opensuse-security-announce/2020-03/msg00027.html)
- [SecurityFocus Advisory](https://www.securityfocus.com/bid/105174) Third Party Advisory, VDB Entry
- [SecurityTracker Advisory](https://www.securitytracker.com/id/1041609) Third Party Advisory, VDB Entry
- [Wireshark Bugzilla Issue](https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14994) Issue Tracking
- [Wireshark Review Commit](https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=f98fbce64cb230e94a2cafc410a3cedad657b485)
- [Debian Security Advisory](https://www.debian.org/security/2018/dsa-4315) Third Party Advisory
- [Wireshark Vendor Advisory](https://www.wireshark.org/security/wnpa-sec-2018-45.html) Vendor Advisory

## Timeline

- **Published**: Aug 30, 2018  
- **Last Modified**: Jun 17, 2026  
- **Status**: Modified

## Frequently Asked Questions

### What is CVE-2018-16056?

### How severe is CVE-2018-16056?

Severity scoring for CVE-2018-16056 is pending analysis. The EPSS model estimates a 3.35% probability of exploitation in the next 30 days.

### How do I fix CVE-2018-16056?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.

## Related CVEs from 2018

- [CVE-2018-16048](/content/cve/CVE-2018-16048/index.html) An issue was discovered in GitLab Community and Enterprise Edition.
- [CVE-2018-16049](/content/cve/CVE-2018-16049/index.html) An issue was discovered in GitLab Community and Enterprise Edition.
- [CVE-2018-1605](/content/cve/CVE-2018-1605/index.html) IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0.
- [CVE-2018-16050](/content/cve/CVE-2018-16050/index.html) An issue was discovered in GitLab Community and Enterprise Edition.
- [CVE-2018-16051](/content/cve/CVE-2018-16051/index.html) An issue was discovered in GitLab Community and Enterprise Edition.
- [CVE-2018-16055](/content/cve/CVE-2018-16055/index.html) An authenticated command injection vulnerability exists.
- [CVE-2018-16057](/content/cve/CVE-2018-16057/index.html) In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16.
- [CVE-2018-16058](/content/cve/CVE-2018-16058/index.html) In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16.
- [CVE-2018-16059](/content/cve/CVE-2018-16059/index.html) Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices.
- [CVE-2018-1606](/content/cve/CVE-2018-1606/index.html) IBM Jazz based applications.
- [CVE-2018-16060](/content/cve/CVE-2018-16060/index.html) Mitsubishi Electric Europe B.V. SmartRTU devices.
- [CVE-2018-16061](/content/cve/CVE-2018-16061/index.html) Mitsubishi Electric Europe B.V. SmartRTU devices.
