Your message dated Mon, 31 Aug 2026 13:49:02 +0000
with message-id <[email protected]>
and subject line Bug#1144924: fixed in wireshark 4.4.18-0+deb13u1
has caused the Debian Bug report #1144924,
regarding wireshark: CVE-2026-19694 CVE-2026-19695 CVE-2026-19696
CVE-2026-76879 CVE-2026-76880 CVE-2026-76881 CVE-2026-76882 CVE-2026-76883
CVE-2026-76884 CVE-2026-76885 CVE-2026-76886 CVE-2026-76887 CVE-2026-76888
CVE-2026-76889 CVE-2026-76890 CVE-2026-76891 CVE-2026-76917 CVE-2026-76918
CVE-2026-76919 CVE-2026-76920 CVE-2026-76921 CVE-2026-76922 CVE-2026-76923
CVE-2026-76924 CVE-2026-76926 CVE-2026-76927 CVE-2026-76928 CVE-2026-76929
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144924: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144924
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: wireshark
Version: 4.6.6-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for wireshark.
CVE-2026-19694[0]:
| TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of
| service
CVE-2026-19695[1]:
| Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial
| of service
CVE-2026-19696[2]:
| Ixia IxVeriWave and Vector Informatik BLF file parser crashes in
| 4.6.0 to 4.6.7 allows denial of service on Windows
CVE-2026-76879[3]:
| C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76880[4]:
| RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76881[5]:
| CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76882[6]:
| Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and
| 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76883[7]:
| Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76884[8]:
| ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows
| denial of service
CVE-2026-76885[9]:
| Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76886[10]:
| C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76887[11]:
| Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0
| to 4.4.18 allows denial of service
CVE-2026-76888[12]:
| RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76889[13]:
| UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76890[14]:
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
| of service
CVE-2026-76891[15]:
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
| of service
CVE-2026-76917[16]:
| Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7
| and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76918[17]:
| SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76919[18]:
| ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76920[19]:
| 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76921[20]:
| CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76922[21]:
| Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and
| 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76923[22]:
| Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and
| 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76924[23]:
| Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76926[24]:
| BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76927[25]:
| H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
CVE-2026-76928[26]:
| X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to
| 4.4.18 allows denial of service
CVE-2026-76929[27]:
| Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18
| allows denial of service
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-19694
https://www.cve.org/CVERecord?id=CVE-2026-19694
[1] https://security-tracker.debian.org/tracker/CVE-2026-19695
https://www.cve.org/CVERecord?id=CVE-2026-19695
[2] https://security-tracker.debian.org/tracker/CVE-2026-19696
https://www.cve.org/CVERecord?id=CVE-2026-19696
[3] https://security-tracker.debian.org/tracker/CVE-2026-76879
https://www.cve.org/CVERecord?id=CVE-2026-76879
[4] https://security-tracker.debian.org/tracker/CVE-2026-76880
https://www.cve.org/CVERecord?id=CVE-2026-76880
[5] https://security-tracker.debian.org/tracker/CVE-2026-76881
https://www.cve.org/CVERecord?id=CVE-2026-76881
[6] https://security-tracker.debian.org/tracker/CVE-2026-76882
https://www.cve.org/CVERecord?id=CVE-2026-76882
[7] https://security-tracker.debian.org/tracker/CVE-2026-76883
https://www.cve.org/CVERecord?id=CVE-2026-76883
[8] https://security-tracker.debian.org/tracker/CVE-2026-76884
https://www.cve.org/CVERecord?id=CVE-2026-76884
[9] https://security-tracker.debian.org/tracker/CVE-2026-76885
https://www.cve.org/CVERecord?id=CVE-2026-76885
[10] https://security-tracker.debian.org/tracker/CVE-2026-76886
https://www.cve.org/CVERecord?id=CVE-2026-76886
[11] https://security-tracker.debian.org/tracker/CVE-2026-76887
https://www.cve.org/CVERecord?id=CVE-2026-76887
[12] https://security-tracker.debian.org/tracker/CVE-2026-76888
https://www.cve.org/CVERecord?id=CVE-2026-76888
[13] https://security-tracker.debian.org/tracker/CVE-2026-76889
https://www.cve.org/CVERecord?id=CVE-2026-76889
[14] https://security-tracker.debian.org/tracker/CVE-2026-76890
https://www.cve.org/CVERecord?id=CVE-2026-76890
[15] https://security-tracker.debian.org/tracker/CVE-2026-76891
https://www.cve.org/CVERecord?id=CVE-2026-76891
[16] https://security-tracker.debian.org/tracker/CVE-2026-76917
https://www.cve.org/CVERecord?id=CVE-2026-76917
[17] https://security-tracker.debian.org/tracker/CVE-2026-76918
https://www.cve.org/CVERecord?id=CVE-2026-76918
[18] https://security-tracker.debian.org/tracker/CVE-2026-76919
https://www.cve.org/CVERecord?id=CVE-2026-76919
[19] https://security-tracker.debian.org/tracker/CVE-2026-76920
https://www.cve.org/CVERecord?id=CVE-2026-76920
[20] https://security-tracker.debian.org/tracker/CVE-2026-76921
https://www.cve.org/CVERecord?id=CVE-2026-76921
[21] https://security-tracker.debian.org/tracker/CVE-2026-76922
https://www.cve.org/CVERecord?id=CVE-2026-76922
[22] https://security-tracker.debian.org/tracker/CVE-2026-76923
https://www.cve.org/CVERecord?id=CVE-2026-76923
[23] https://security-tracker.debian.org/tracker/CVE-2026-76924
https://www.cve.org/CVERecord?id=CVE-2026-76924
[24] https://security-tracker.debian.org/tracker/CVE-2026-76926
https://www.cve.org/CVERecord?id=CVE-2026-76926
[25] https://security-tracker.debian.org/tracker/CVE-2026-76927
https://www.cve.org/CVERecord?id=CVE-2026-76927
[26] https://security-tracker.debian.org/tracker/CVE-2026-76928
https://www.cve.org/CVERecord?id=CVE-2026-76928
[27] https://security-tracker.debian.org/tracker/CVE-2026-76929
https://www.cve.org/CVERecord?id=CVE-2026-76929
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: wireshark
Source-Version: 4.4.18-0+deb13u1
Done: Matheus Polkorny <[email protected]>
We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <[email protected]> (supplier of updated wireshark package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 23 Aug 2026 12:34:57 -0300
Source: wireshark
Architecture: source
Version: 4.4.18-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Balint Reczey <[email protected]>
Changed-By: Matheus Polkorny <[email protected]>
Closes: 1142268 1144924
Changes:
wireshark (4.4.18-0+deb13u1) trixie-security; urgency=medium
.
* Team upload.
* New upstream version 4.4.18 (Closes: #1142268, #1144924)
- CVE-2026-15163: Multiple loops in dissectors, allows DoS
- CVE-2026-15164: Crash in ciscodump, allows DoS
- CVE-2026-15166: IEEE 802.11 dissector crash, allows DoS
- CVE-2026-15167: DBS Etherwatch parser crash, allows DoS
- CVE-2026-15168: BLF parser, allows information disclosure
- CVE-2026-15169: UMTS FP dissector crash, allows DoS
- CVE-2026-15170: Z39.50 dissector crash, allows DoS
- CVE-2026-15171: SSH dissector crash, allows DoS
- CVE-2026-15172: FMP/NOTIFY dissector crash, allows DoS
- CVE-2026-15174: Catapult DCT2000 dissector crash, allows DoS
- CVE-2026-76879: C12.22 dissector crash, allows DoS
- CVE-2026-76880: RRC dissector crash, allows DoS
- CVE-2026-76881: CMS dissector crash, allows DoS
- CVE-2026-76882: Bluetooth Attribute dissector crash, allows DoS
- CVE-2026-76883: Catapult DCT2000 parser crash, allows DoS
- CVE-2026-76884: ERF parser crash, allows DoS
- CVE-2026-76885: Tektronix K12xx parser crash, allows DoS
- CVE-2026-76886: C12.22 dissector crash, allows DoS
- CVE-2026-76887: Dissection engine crash, allows DoS
- CVE-2026-76888: RDP dissector crash, allows DoS
- CVE-2026-76889: UMTS FP dissector crash, allows DoS
- CVE-2026-76890: Crash in sharkd, allows DoS
- CVE-2026-76891: Crash in sharkd, allows DoS
- CVE-2026-76917: Bluetooth AVRCP dissector crash, allows DoS
- CVE-2026-76918: SSH dissector crash, allows DoS
- CVE-2026-76919: ESS dissector crash, allows DoS
- CVE-2026-76920: 3gpp phone log parser crash, allows DoS
- CVE-2026-76921: CMS dissector crash, allows DoS
- CVE-2026-76922: Bluetooth BR/EDR FHS dissector crash, allows DoS
- CVE-2026-76923: Bluetooth HFP dissector crash, allows DoS
- CVE-2026-76924: Kerberos dissector crash, allows DoS
- CVE-2026-76926: BUSMASTER parser abnormal exit, allows DoS
- CVE-2026-76927: H.245 dissector crash, allows DoS
- CVE-2026-76928: X.509IF dissector crash, allows DoS
- CVE-2026-76929: Pcapng parser crash, allows DoS
Checksums-Sha1:
925f6788f2954b3e2a0b420f270ea5e687f3042d 3470 wireshark_4.4.18-0+deb13u1.dsc
1b56d51659ad0478667b7ab67f947c3d1361363d 50805713 wireshark_4.4.18.orig.tar.bz2
4896c826d13f5489ee9f94d3a6c1baec7e69a0ea 87340
wireshark_4.4.18-0+deb13u1.debian.tar.xz
44940dd539739d6719016220c56de89dcdeafa88 6495
wireshark_4.4.18-0+deb13u1_source.buildinfo
Checksums-Sha256:
04b2e2abeb34fe02de959d5543a040e5a6b782f2c6e2f8a2e355a0d3d4c9d878 3470
wireshark_4.4.18-0+deb13u1.dsc
5b0b9157e48edffbc2434a93d8cb8a8c67ee9cfc046188cd3664e96744a3697d 50805713
wireshark_4.4.18.orig.tar.bz2
1c82ac2c64c70a30a9090822317216225a9e6563f3799c4ac8df0aed547499ce 87340
wireshark_4.4.18-0+deb13u1.debian.tar.xz
6018d663dc52621611850b09b02e94a3c8dceb57e339b66e712b0997823b4e21 6495
wireshark_4.4.18-0+deb13u1_source.buildinfo
Files:
fcde05d15302194a4e6a1cc9f172e21a 3470 net optional
wireshark_4.4.18-0+deb13u1.dsc
4b683419e6e76dfcb44cf467c9a892aa 50805713 net optional
wireshark_4.4.18.orig.tar.bz2
7527fca341086b7b89304656972c3262 87340 net optional
wireshark_4.4.18-0+deb13u1.debian.tar.xz
25a52819ac74a434c598b8d063338fdd 6495 net optional
wireshark_4.4.18-0+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmqPqOUACgkQt4M9ggJ8
mQvhZw//c0oorCxpkLq+z4j/fosqWzJcrJ3zyiW1Ou/RLvCcI+Pl1Brcxk8ZeUSu
YyIxwmy4Dt7zkQzJf7RxrOZcpeq4+n4TD6mDgaKRoWRlhcZTW+Tdavo6m3sGpiLG
2OatgtEx9UKPQfCuZjPtIjd/IXqc+OvjDETUnSR8IYv2EJUKyuFuqrVYD3ocR2pb
mp553SdvjcS+yKWAQfNjMtJoeaZH/bV8Noy6XMBUOYE0iPulZowvjfCg4YFjKfdc
fS3kj60e9pwJFgyWgJPEpnfCiQBQhlnDbacGB5lF3vHzg0CISfJTadM+LVXpdDRe
NTNw6SQuQZxJdWqUv3khD9Nqr1oZetHZlzh84CsjSETkBTYvuEMMuLLDC0D5SASX
vQi2csyulpFOoX72jGPzSbyidjSbN193Y/jo3gD2ccuPvjYNp4fv2uyTxRW45A4J
Odt1WCUGjs1roDP/n0JfC35yDdFNcBmsFeA80PZW4rQrOhtS/84lmb8vsU8m5J1h
WfOhmBAg4Awh8hl1Hz8T8xlDdYt9yLbnjilI+3aYWn+fo9L6fW3X6UC83xjlY1p3
yKioBaLP5jpQRf9XQhL0Lf2+r80rWnuTuXu5WlMXVrj4EW7i8vhCD/cLAl1xYm1J
/tLASe+TbcwU0JRQE04/mYUcJcA9YsYs1CJ2Vvnqqo2SrR6/a80=
=WYG1
-----END PGP SIGNATURE-----
pgp4SC3IuVLDA.pgp
Description: PGP signature
--- End Message ---