cognitive cybersecurity intelligence

News and Analysis

Search

Wireshark 4.6.8 Released With Patch for 28 Vulnerabilities That Lead to Crashes

Wireshark 4.6.8 Released With Patch for 28 Vulnerabilities That Lead to Crashes

The Wireshark Foundation has officially rolled out Wireshark 4.6.8, a security update that patches 28 distinct vulnerabilities capable of triggering application crashes across the network protocol analyzer.

As the world’s most widely used tool for network troubleshooting, protocol analysis, software development, and education, Wireshark is a staple for security operations centers (SOCs) and network engineering teams.

Addressing these Wireshark DoS vulnerabilities is critical to preventing unexpected analysis outages during live packet captures or incident response workflows.

Wireshark 4.6.8 Patches 28 Vulnerabilities

Tracked under security advisories wnpa-sec-2026-64 through wnpa-sec-2026-91, the patched vulnerabilities span a broad range of protocol dissectors and internal components.

AdvisoryAffected componentVulnerability detailRelated issue(s)wnpa-sec-2026-64sharkdsharkd utility crash21395wnpa-sec-2026-65sharkdsharkd utility crash21399wnpa-sec-2026-66UMTS FP dissectorProtocol dissector crash21413wnpa-sec-2026-67RDP dissectorProtocol dissector crash21396wnpa-sec-2026-68TTX Logger parserCapture-file parser crash21389wnpa-sec-2026-69Dissection engineReassembly engine crash21423wnpa-sec-2026-70BUSMASTER parserAbnormal exit while parsing files21435wnpa-sec-2026-71Tektronix K12xx parserCapture-file parser crash21414wnpa-sec-2026-72Endace ERF parserCapture-file parser crash21415wnpa-sec-2026-73Bluetooth ATT dissectorProtocol dissector crash21424wnpa-sec-2026-74Catapult DCT2000 parserCapture-file parser crash21427wnpa-sec-2026-75C12.22 dissectorProtocol dissector crash21439wnpa-sec-2026-76CMS dissectorProtocol dissector crash21446wnpa-sec-2026-77H.245 dissectorProtocol dissector crash21447wnpa-sec-2026-78Kerberos dissectorProtocol dissector crash21449wnpa-sec-2026-79Bluetooth HFP dissectorProtocol dissector crash21451wnpa-sec-2026-80Bluetooth BR/EDR FHS dissectorProtocol dissector crash21452wnpa-sec-2026-813GPP phone-log parserCapture-file parser crash21454wnpa-sec-2026-82Ixia IxVeriWave and Vector BLF parsersParser crashes on Windows21455wnpa-sec-2026-83CMS dissectorProtocol dissector crash21457, 21458wnpa-sec-2026-84pcapng parserCapture-file parser crash21460wnpa-sec-2026-85SSH dissectorProtocol dissector crash21465wnpa-sec-2026-86ESS dissectorProtocol dissector crash21467wnpa-sec-2026-87X.509IF dissectorProtocol dissector crash21469wnpa-sec-2026-88RRC dissectorProtocol dissector crash21478wnpa-sec-2026-89C12.22 dissectorProtocol dissector crash21480wnpa-sec-2026-90Gammu DCT3 parserCapture-file parser crash21475wnpa-sec-2026-91Bluetooth AVRCP dissectorProtocol dissector crash21488

Several flaws directly impact the sharkd headless daemon, while others target protocol dissectors used across enterprise, wireless, and industrial communications.

Key Affected Dissectors:

Enterprise & Security Protocols: Remote Desktop Protocol (RDP), Kerberos, SSH, H.245, Cryptographic Message Syntax (CMS), and X.509IF.

Wireless & Cellular Stack: Multiple Bluetooth profiles (ATT, HFP, AVRCP, BR/EDR FHS) alongside UMTS FP and RRC cellular protocol dissectors.

Industrial & Utilities: C12.22 smart-metering protocol, which appeared twice across the advisory list.

Most of these vulnerabilities stem from improper handling of malformed or maliciously crafted packet data. An attacker on a monitored network segment or one who tricks an analyst into opening a crafted capture file can trigger a denial-of-service (DoS) condition, crashing the dissection engine.

Historically, unpatched Wireshark code execution risks and dissector crashes have presented severe operational risks when analysts process untrusted network files.

Notably, advisory wnpa-sec-2026-87, involving the X.509IF dissector, carries a pending CVE identifier, signaling its forthcoming inclusion in broader national vulnerability databases.

File parsing components represented another major area of exposure in this release. Wireshark’s input modules for TTX Logger, BUSMASTER, Tektronix K12xx, Endace ERF, Catapult DCT2000, Gammu DCT3 trace files, and 3gpp phone logs each received patches for parser crash conditions.

Windows-specific crash fixes were also deployed for the Ixia IxVeriWave and Vector Informatik BLF file readers.

As detailed in the official Wireshark 4.6.8 Release Notes, the release addresses a long list of stability, memory handling, and accuracy issues beyond core security advisories.

Buffer & Memory Protection: Fixed a stack buffer overflow in the K12/RF5 writer, an out-of-bounds read in the BLF writer when handling truncated VLAN-tagged Ethernet frames, and a NULL-pointer dereference in the KNXIP Secure Wrapper decryption path.

Recursion Guardrails: Corrected a stack-exhaustion flaw triggered by deeply nested NetLog JSON payloads.

5G Telemetry Accuracy: Corrected decoding logic for 5G NAS information elements, including S-NSSAI location validity, UE security capability, and SOR transparent container fields.

UI Performance: Resolved a Windows-specific UI delay affecting the File Capture Properties dialog.

Tracking ongoing Wireshark security updates ensures that network monitoring tools remain resilient against unexpected crash vectors.

Affected Component / ModuleVulnerability ID / TypeOperational Impactsharkd Daemon & Corewnpa-sec-2026-64 to 91Denial-of-Service / Engine crash via malformed inputX.509IF Dissectorwnpa-sec-2026-87 (CVE Pending)Parsing crash when processing invalid X.509 structuresK12 / RF5 File WriterStack Buffer OverflowMemory corruption / Crash during file write operationsBLF File WriterOut-of-bounds ReadApplication crash on truncated VLAN-tagged framesKNXIP Secure WrapperNULL-Pointer DereferenceDecryption path crash during payload analysisNetLog JSON ParserStack ExhaustionApplication crash on deeply nested JSON objects

While Wireshark 4.6.8 does not add brand-new protocol support, it updates dissection capability for ASN.1 BER, ASTERIX, GTPv2, RELOAD, and Rlogin, alongside updated capture file handling for Daintree SNA and pcapng formats.

Additionally, the release documents a packaging adjustment introduced in the 4.6.x release line: on most UN*X distributions, extcap binaries now reside within the libexec directory rather than the standard library path.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Wireshark 4.6.8 Released With Patch for 28 Vulnerabilities That Lead to Crashes appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts