PT-2021-5595 · Wireshark+5 · Wireshark+5

Published

2021-11-17

·

Updated

2025-06-04

·

CVE-2021-39929

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.2.0 through 3.2.17 Wireshark versions 3.4.0 through 3.4.9
Description The issue is caused by uncontrolled recursion in the Bluetooth DHT dissector. This can be exploited by a remote attacker to cause a denial of service by injecting specially crafted packets or using a crafted capture file.
Recommendations For Wireshark versions 3.2.0 through 3.2.17, update to a version that fixes the uncontrolled recursion issue in the Bluetooth DHT dissector. For Wireshark versions 3.4.0 through 3.4.9, update to a version that fixes the uncontrolled recursion issue in the Bluetooth DHT dissector. As a temporary workaround, consider disabling the Bluetooth DHT dissector until a patch is available.

Exploit

Fix

DoS

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3354
ALT-PU-2022-1096
ALT-PU-2022-1368
ALT-PU-2022-1599
AZL-7416
BDU:2022-00029
CVE-2021-39929
DLA-2849-1
DSA-5019-1
MGASA-2021-0518
OPENSUSE-SU-2021:1566-1
OPENSUSE-SU-2021:3938-1
OPENSUSE-SU-2021_1566-1
OPENSUSE-SU-2021_3938-1
OPENSUSE-SU-2024:11641-1
SUSE-SU-2021:3938-1
USN-7552-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wireshark