The Wireshark Foundation has officially rolled out Wireshark 4.6.8, a security update that patches 28 distinct vulnerabilities capable of triggering application crashes across the network protocol analyzer.
As the world’s most widely used tool for network troubleshooting, protocol analysis, software development, and education, Wireshark is a staple for security operations centers (SOCs) and network engineering teams.
Addressing these Wireshark DoS vulnerabilities is critical to preventing unexpected analysis outages during live packet captures or incident response workflows.
Tracked under security advisories wnpa-sec-2026-64 through wnpa-sec-2026-91, the patched vulnerabilities span a broad range of protocol dissectors and internal components.
| Advisory | Affected component | Vulnerability detail | Related issue(s) |
|---|---|---|---|
| wnpa-sec-2026-64 | sharkd | sharkd utility crash | 21395 |
| wnpa-sec-2026-65 | sharkd | sharkd utility crash | 21399 |
| wnpa-sec-2026-66 | UMTS FP dissector | Protocol dissector crash | 21413 |
| wnpa-sec-2026-67 | RDP dissector | Protocol dissector crash | 21396 |
| wnpa-sec-2026-68 | TTX Logger parser | Capture-file parser crash | 21389 |
| wnpa-sec-2026-69 | Dissection engine | Reassembly engine crash | 21423 |
| wnpa-sec-2026-70 | BUSMASTER parser | Abnormal exit while parsing files | 21435 |
| wnpa-sec-2026-71 | Tektronix K12xx parser | Capture-file parser crash | 21414 |
| wnpa-sec-2026-72 | Endace ERF parser | Capture-file parser crash | 21415 |
| wnpa-sec-2026-73 | Bluetooth ATT dissector | Protocol dissector crash | 21424 |
| wnpa-sec-2026-74 | Catapult DCT2000 parser | Capture-file parser crash | 21427 |
| wnpa-sec-2026-75 | C12.22 dissector | Protocol dissector crash | 21439 |
| wnpa-sec-2026-76 | CMS dissector | Protocol dissector crash | 21446 |
| wnpa-sec-2026-77 | H.245 dissector | Protocol dissector crash | 21447 |
| wnpa-sec-2026-78 | Kerberos dissector | Protocol dissector crash | 21449 |
| wnpa-sec-2026-79 | Bluetooth HFP dissector | Protocol dissector crash | 21451 |
| wnpa-sec-2026-80 | Bluetooth BR/EDR FHS dissector | Protocol dissector crash | 21452 |
| wnpa-sec-2026-81 | 3GPP phone-log parser | Capture-file parser crash | 21454 |
| wnpa-sec-2026-82 | Ixia IxVeriWave and Vector BLF parsers | Parser crashes on Windows | 21455 |
| wnpa-sec-2026-83 | CMS dissector | Protocol dissector crash | 21457, 21458 |
| wnpa-sec-2026-84 | pcapng parser | Capture-file parser crash | 21460 |
| wnpa-sec-2026-85 | SSH dissector | Protocol dissector crash | 21465 |
| wnpa-sec-2026-86 | ESS dissector | Protocol dissector crash | 21467 |
| wnpa-sec-2026-87 | X.509IF dissector | Protocol dissector crash | 21469 |
| wnpa-sec-2026-88 | RRC dissector | Protocol dissector crash | 21478 |
| wnpa-sec-2026-89 | C12.22 dissector | Protocol dissector crash | 21480 |
| wnpa-sec-2026-90 | Gammu DCT3 parser | Capture-file parser crash | 21475 |
| wnpa-sec-2026-91 | Bluetooth AVRCP dissector | Protocol dissector crash | 21488 |
Several flaws directly impact the sharkd headless daemon, while others target protocol dissectors used across enterprise, wireless, and industrial communications.
Key Affected Dissectors:
Most of these vulnerabilities stem from improper handling of malformed or maliciously crafted packet data. An attacker on a monitored network segment or one who tricks an analyst into opening a crafted capture file can trigger a denial-of-service (DoS) condition, crashing the dissection engine.
Historically, unpatched Wireshark code execution risks and dissector crashes have presented severe operational risks when analysts process untrusted network files.
Notably, advisory wnpa-sec-2026-87, involving the X.509IF dissector, carries a pending CVE identifier, signaling its forthcoming inclusion in broader national vulnerability databases.
File parsing components represented another major area of exposure in this release. Wireshark’s input modules for TTX Logger, BUSMASTER, Tektronix K12xx, Endace ERF, Catapult DCT2000, Gammu DCT3 trace files, and 3gpp phone logs each received patches for parser crash conditions.
Windows-specific crash fixes were also deployed for the Ixia IxVeriWave and Vector Informatik BLF file readers.
As detailed in the official Wireshark 4.6.8 Release Notes, the release addresses a long list of stability, memory handling, and accuracy issues beyond core security advisories.
Tracking ongoing Wireshark security updates ensures that network monitoring tools remain resilient against unexpected crash vectors.
| Affected Component / Module | Vulnerability ID / Type | Operational Impact |
sharkd Daemon & Core | wnpa-sec-2026-64 to 91 | Denial-of-Service / Engine crash via malformed input |
| X.509IF Dissector | wnpa-sec-2026-87 (CVE Pending) | Parsing crash when processing invalid X.509 structures |
| K12 / RF5 File Writer | Stack Buffer Overflow | Memory corruption / Crash during file write operations |
| BLF File Writer | Out-of-bounds Read | Application crash on truncated VLAN-tagged frames |
| KNXIP Secure Wrapper | NULL-Pointer Dereference | Decryption path crash during payload analysis |
| NetLog JSON Parser | Stack Exhaustion | Application crash on deeply nested JSON objects |
While Wireshark 4.6.8 does not add brand-new protocol support, it updates dissection capability for ASN.1 BER, ASTERIX, GTPv2, RELOAD, and Rlogin, alongside updated capture file handling for Daintree SNA and pcapng formats.
Additionally, the release documents a packaging adjustment introduced in the 4.6.x release line: on most UN*X distributions, extcap binaries now reside within the libexec directory rather than the standard library path.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…
The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…
Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…
The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…
Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…