The Wireshark Foundation has officially rolled out Wireshark 4.6.8, a security update that patches 28 distinct vulnerabilities capable of triggering application crashes across the network protocol analyzer.
As the world’s most widely used tool for network troubleshooting, protocol analysis, software development, and education, Wireshark is a staple for security operations centers (SOCs) and network engineering teams.
Addressing these Wireshark DoS vulnerabilities is critical to preventing unexpected analysis outages during live packet captures or incident response workflows.
Tracked under security advisories wnpa-sec-2026-64 through wnpa-sec-2026-91, the patched vulnerabilities span a broad range of protocol dissectors and internal components.
| Advisory | Affected component | Vulnerability detail | Related issue(s) |
|---|---|---|---|
| wnpa-sec-2026-64 | sharkd | sharkd utility crash | 21395 |
| wnpa-sec-2026-65 | sharkd | sharkd utility crash | 21399 |
| wnpa-sec-2026-66 | UMTS FP dissector | Protocol dissector crash | 21413 |
| wnpa-sec-2026-67 | RDP dissector | Protocol dissector crash | 21396 |
| wnpa-sec-2026-68 | TTX Logger parser | Capture-file parser crash | 21389 |
| wnpa-sec-2026-69 | Dissection engine | Reassembly engine crash | 21423 |
| wnpa-sec-2026-70 | BUSMASTER parser | Abnormal exit while parsing files | 21435 |
| wnpa-sec-2026-71 | Tektronix K12xx parser | Capture-file parser crash | 21414 |
| wnpa-sec-2026-72 | Endace ERF parser | Capture-file parser crash | 21415 |
| wnpa-sec-2026-73 | Bluetooth ATT dissector | Protocol dissector crash | 21424 |
| wnpa-sec-2026-74 | Catapult DCT2000 parser | Capture-file parser crash | 21427 |
| wnpa-sec-2026-75 | C12.22 dissector | Protocol dissector crash | 21439 |
| wnpa-sec-2026-76 | CMS dissector | Protocol dissector crash | 21446 |
| wnpa-sec-2026-77 | H.245 dissector | Protocol dissector crash | 21447 |
| wnpa-sec-2026-78 | Kerberos dissector | Protocol dissector crash | 21449 |
| wnpa-sec-2026-79 | Bluetooth HFP dissector | Protocol dissector crash | 21451 |
| wnpa-sec-2026-80 | Bluetooth BR/EDR FHS dissector | Protocol dissector crash | 21452 |
| wnpa-sec-2026-81 | 3GPP phone-log parser | Capture-file parser crash | 21454 |
| wnpa-sec-2026-82 | Ixia IxVeriWave and Vector BLF parsers | Parser crashes on Windows | 21455 |
| wnpa-sec-2026-83 | CMS dissector | Protocol dissector crash | 21457, 21458 |
| wnpa-sec-2026-84 | pcapng parser | Capture-file parser crash | 21460 |
| wnpa-sec-2026-85 | SSH dissector | Protocol dissector crash | 21465 |
| wnpa-sec-2026-86 | ESS dissector | Protocol dissector crash | 21467 |
| wnpa-sec-2026-87 | X.509IF dissector | Protocol dissector crash | 21469 |
| wnpa-sec-2026-88 | RRC dissector | Protocol dissector crash | 21478 |
| wnpa-sec-2026-89 | C12.22 dissector | Protocol dissector crash | 21480 |
| wnpa-sec-2026-90 | Gammu DCT3 parser | Capture-file parser crash | 21475 |
| wnpa-sec-2026-91 | Bluetooth AVRCP dissector | Protocol dissector crash | 21488 |
Several flaws directly impact the sharkd headless daemon, while others target protocol dissectors used across enterprise, wireless, and industrial communications.
Key Affected Dissectors:
Most of these vulnerabilities stem from improper handling of malformed or maliciously crafted packet data. An attacker on a monitored network segment or one who tricks an analyst into opening a crafted capture file can trigger a denial-of-service (DoS) condition, crashing the dissection engine.
Historically, unpatched Wireshark code execution risks and dissector crashes have presented severe operational risks when analysts process untrusted network files.
Notably, advisory wnpa-sec-2026-87, involving the X.509IF dissector, carries a pending CVE identifier, signaling its forthcoming inclusion in broader national vulnerability databases.
File parsing components represented another major area of exposure in this release. Wireshark’s input modules for TTX Logger, BUSMASTER, Tektronix K12xx, Endace ERF, Catapult DCT2000, Gammu DCT3 trace files, and 3gpp phone logs each received patches for parser crash conditions.
Windows-specific crash fixes were also deployed for the Ixia IxVeriWave and Vector Informatik BLF file readers.
As detailed in the official Wireshark 4.6.8 Release Notes, the release addresses a long list of stability, memory handling, and accuracy issues beyond core security advisories.
Tracking ongoing Wireshark security updates ensures that network monitoring tools remain resilient against unexpected crash vectors.
| Affected Component / Module | Vulnerability ID / Type | Operational Impact |
sharkd Daemon & Core | wnpa-sec-2026-64 to 91 | Denial-of-Service / Engine crash via malformed input |
| X.509IF Dissector | wnpa-sec-2026-87 (CVE Pending) | Parsing crash when processing invalid X.509 structures |
| K12 / RF5 File Writer | Stack Buffer Overflow | Memory corruption / Crash during file write operations |
| BLF File Writer | Out-of-bounds Read | Application crash on truncated VLAN-tagged frames |
| KNXIP Secure Wrapper | NULL-Pointer Dereference | Decryption path crash during payload analysis |
| NetLog JSON Parser | Stack Exhaustion | Application crash on deeply nested JSON objects |
While Wireshark 4.6.8 does not add brand-new protocol support, it updates dissection capability for ASN.1 BER, ASTERIX, GTPv2, RELOAD, and Rlogin, alongside updated capture file handling for Daintree SNA and pcapng formats.
Additionally, the release documents a packaging adjustment introduced in the 4.6.x release line: on most UN*X distributions, extcap binaries now reside within the libexec directory rather than the standard library path.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…