HomeSecurityWireshark 4.6.8 fixes 28 vulnerabilities and 25 bugs

Wireshark 4.6.8 fixes 28 vulnerabilities and 25 bugs

Wireshark 4.6.8 brings an extensive set of security fixes, addressing 28 vulnerabilities and 25 other bugs. The update concerns the popular network protocol analyzer and is recommended for those who open log files or examine untrusted traffic.

Wireshark 4.6.8 security fixes

The SANS Internet Storm Center announcement lists the release as August 16, while the official project notes describe the individual fixes. Wireshark is not a service that is typically exposed directly to the internet, but it processes data that may have been generated by third parties.

See also: Wireshark 4.6.6 fixes ROHC Parser vulnerabilities

What Wireshark 4.6.8 fixes

The official documentation for the release lists issues ranging from the Bluetooth AVRCP and HFP parsers to the SSH, Kerberos, RDP, CMS, RRC, and X.509IF protocols. Most of the descriptions concern the parser crashing when processing specially crafted packets or log files.

The fixes also cover file readers for pcapng, Gammu DCT3, Catapult DCT2000, Tektronix K12xx, and BLF. In some cases the problem concerns the packet reassembly mechanism, while in others a specific protocol parser or the sharkd utility.

The list is important because Wireshark supports a large number of protocols and capture formats. A file that appears harmless to a user can trigger a different code path depending on its content. The fixes don't just apply to the graphical application, but also to individual tools used in servers or automation pipelines.

The official Wireshark security advisories shows that several of the fixes are available in both the 4.6.8 and 4.4.18 series. For advisory wnpa-sec-2026-90, which concerns the Gammu DCT3 analyzer, the fixed version is 4.6.8, while wnpa-sec-2026-91 concerns the Bluetooth AVRCP analyzer.

Wireshark 4.6.8 protocol analyzer vulnerabilities

How can the risk arise?

A maliciously crafted log file or malformed packet can lead to an unexpected application termination when analyzed by a vulnerable version. The result does not automatically mean remote code execution, but it can interrupt an audit process, delay incident analysis, or affect an automated system using Wireshark tools.

Special care is needed in groups that exchange pcapng files, in malicious traffic analysis labs, and on stations where the TShark or sharkd utilities are used. Reading data from an unknown source should be done in a controlled environment, even after installing the update.

The fact that several tips describe a crash does not diminish their importance. In an operations center, a breakdown of an analysis station can leave an incident uncontrolled at a time when analysts need a quick picture of the traffic. The installation of the release should therefore be part of the update management process.

See also: GitLab fixes 8 security vulnerabilities in CE and EE

Wireshark 4.6.8 crash risk

The recommended update

Wireshark says anyone using a vulnerable version should consider upgrading. Wireshark 4.6.8 is the stable release of the 4.6 series, while 4.4.18 covers organizations that remain on the 4.4 series. Administrators should confirm which version their distribution supports and schedule an installation from the official packages.

After the upgrade, it is necessary to check the automations that call TShark or sharkd, as well as the third-party tools that read the capture files. At the same time, it is useful to limit access to untrusted files and keep the original data in backup copies, so that the technical team can safely repeat the analysis.

See also: Wireshark 4.6.7 fixes 12 security issues across multiple protocols

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Wireshark 4.6.8 secure update

The SecNews technical team recommends updating before the next use of logs from external sources. The 28 fixes do not all address the same attack scenario, but the range of affected analysts makes the upgrade a practical measure with immediate benefit.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS