Wireshark has launched model 4.6.8, which addresses safety vulnerabilities in 28 recognized points that would result in crashes, irregular exits, memory-safety issues, and denial-of-service circumstances when the community protocol analyzer handles specifically crafted site visitors or seize recordsdata.
This replace is especially essential for safety analysts, incident responders, community directors, and researchers who regularly work with untrusted packet captures, analyze diagnostic traces, or examine advanced protocol site visitors.
Wireshark 4.6.8 Launched
Wireshark is a extensively used, open-source community protocol analyzer maintained by the Wireshark Basis. It permits customers to seize, examine, decode, and troubleshoot community communications throughout a broad vary of protocols and file codecs.
As a result of the applying processes probably attacker-controlled enter, together with dwell site visitors, PCAP/PCAPNG captures, Bluetooth traces, telecom logs, and vendor-specific seize codecs, vulnerabilities in its parsers and dissectors can pose vital dangers to customers analyzing suspicious recordsdata.
The 4.6.8 launch addresses vulnerabilities tracked from WNPA-SEC-2026-64 to WNPA-SEC-2026-91. A good portion of the fastened vulnerabilities pertains to crashes in protocol dissectors, together with these for UMTS FP, RDP, Bluetooth Attribute Protocol, C12.22, CMS, H.245, Kerberos, SSH, ESS, RRC, X.509IF, Bluetooth HFP, Bluetooth BR/EDR FHS, and Bluetooth AVRCP.
Affected programs would possibly crash whereas making an attempt to decode malformed protocol knowledge. Whereas the discharge notes primarily describe these points as crashes, organizations ought to deal with malformed seize recordsdata and site visitors samples as untrusted till they’ve upgraded.
A number of flaws additionally affect sharkd, Wireshark’s daemon-oriented element that gives packet-analysis capabilities to different purposes. Particularly, WNPA-SEC-2026-64 and WNPA-SEC-2026-65 resolve crash circumstances in sharkd.
Environments that combine Wireshark instruments into automated evaluation pipelines, net interfaces, or collaborative forensic platforms ought to prioritize assessing their publicity to sharkd and promptly making use of the replace.
Seize-file parsing is one other key focus of this launch. Wireshark 4.6.8 fixes points in a number of codecs, together with TTX Logger, BUSMASTER, Tektronix K12xx, Endace ERF, Catapult DCT2000, 3GPP cellphone logs, Ixia IxVeriWave, Vector Informatik BLF, pcapng, and Gammu DCT3 processing.
These codecs are generally encountered in enterprise networking, automotive testing, telecom evaluation, and {hardware} troubleshooting. An attacker might exploit a malicious seize file, main an analyst to open it throughout an investigation, making it essential for defensive groups to reinforce file-parser safety.
Along with the listed safety advisories, the replace resolves different stability and memory-handling defects. Noteworthy fixes embrace addressing a stack buffer overflow within the K12/RF5 author, an out-of-bounds learn within the BLF author, a recursion situation in DLMS/COSEM decoding that would exhaust the stack, a NULL-pointer dereference in KNX/IP Safe Wrapper processing, and a worldwide out-of-bounds learn attributable to a signed Bluetooth snoop size in androiddump.
Wireshark additionally fastened deep NetLog JSON nesting that would exhaust the native stack and addressed an integer-overflow subject involving unbounded Daintree timestamp fractions.
The discharge additional enhances decoding for a number of 5G NAS data components, correcting errors associated to S-NSSAI location validity, NSAG data, UE safety functionality, registration wait vary, Prolonged CAG data, and Service on Request containers.
Though Wireshark 4.6.8 doesn’t introduce new protocol assist, it improves assist throughout quite a few protocols and seize codecs, reinforcing the instrument’s reliability for contemporary community and telecom evaluation.
Customers are inspired to improve their Wireshark installations to model 4.6.8 as quickly as operationally possible. Safety groups must also replace any evaluation workstations, sandboxes, automated pipelines, and shared forensic environments that course of untrusted packet captures.
Cease new phishing & malware earlier than they compromise your corporation. Combine dwell intel from 15K SOCs all over the world









