Wireshark 4.6.7 Fixes 12 Security Flaws Causing Crashes and Infinite Loops

Wireshark has released version 4.6.7, addressing 12 security vulnerabilities that could lead to application crashes, information disclosure, and resource exhaustion via maliciously crafted network traffic or capture files.

Wireshark is a widely used open-source network protocol analyzer used by security researchers, network administrators, incident responders, and developers to inspect packet captures and troubleshoot network communications.

Because the tool processes untrusted packet data and capture files, flaws in its protocol dissectors and file parsers can expose users to denial-of-service risks when opening attacker-controlled content.

Wireshark 4.6.7 Fixes 12 Security Flaws

The latest release fixes security advisories tracked as WNPA-SEC-2026-52 through WNPA-SEC-2026-63. Most of the reported issues involve crashes in protocol dissectors, the components that decode network traffic into human-readable fields.

Several vulnerabilities could cause Wireshark to terminate unexpectedly while analyzing malformed packets. The affected dissectors include Catapult DCT2000, SSH, TLS Encrypted Client Hello (ECH), IEEE 802.11802.11802.11, Z39.50, and UMTS FP.

The Catapult DCT2000 issue, tracked as WNPA-SEC-2026-52, was linked to insufficient validation of header data, which could have triggered a buffer overflow or segmentation fault.

Wireshark also resolved a crash in TLS ECH decryption, a feature used to inspect encrypted TLS handshakes when suitable decryption material is available. Other fixes address crashes in the SSH and IEEE 802.11 dissectors.

These components are particularly significant for enterprise security teams, as SSH and wireless traffic are commonly examined during network troubleshooting, threat hunting, and forensic investigations.

Wireshark 4.6.7 also fixes a crash affecting the Ciscodump extcap interface. Extcap utilities extend Wireshark’s packet-capture capabilities by allowing it to collect traffic from external sources and devices.

The update resolves a large-loop condition in the FMP/NOTIFY dissector, tracked under WNPA-SEC-2026-54. It additionally fixes multiple infinite-loop vulnerabilities across protocol dissectors under WNPA-SEC-2026-61.

Infinite loops can cause Wireshark to consume excessive CPU resources or become unresponsive while processing a specially crafted packet capture. In operational environments, this could disrupt analysis workflows and delay response activities while analysts review suspicious captures.

Two capture-file parsing vulnerabilities were also addressed. WNPA-SEC-2026-53 fixes a crash in the pcapng parser, while WNPA-SEC-2026-62 resolves a crash in the DBS Etherwatch file parser.

The pcapng format is extensively used for storing packet captures, making parser hardening especially important for teams that exchange captures with third parties or ingest files from monitoring platforms.

Additionally, WNPA-SEC-2026-60 fixes an information disclosure issue in the BLF file parser. BLF files are commonly associated with automotive network analysis and can contain data from CAN-based vehicle systems.

Beyond the security advisories, the release fixes multiple stability and parsing defects identified through fuzz testing.

These include a heap buffer overflow in the Android Logcat parser, a use-after-free condition in the Ethernet POWERLINK dissector, memory leaks, UTF-888 processing issues, and a heap corruption crash caused by saved configuration data.

Wireshark 4.6.7 also updates Windows installers to use Visual Studio 2026. No new protocol support was added, but support was updated for numerous protocols and capture formats, including DNS, BACapp, DCERPC, H.265, IEEE 802.11, SSH, Android Logcat, BLF, Netlog, and pcapng.

Organizations and individual users should promptly update to Wireshark 4.6.7, particularly when opening packet captures, log files, or wireless traffic obtained from untrusted sources. Analysts should also avoid processing suspicious capture files on sensitive systems until updates have been applied.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories