CyberSecurityNews

Wireshark 4.6.9 Fixes 19 Vulnerabilities Including Code Execution Via Malicious Packet


Wireshark has released version 4.6.9, a security-focused update that addresses 19 documented vulnerabilities across protocol dissectors, capture-file parsers, the Sharkd utility, and configuration-profile handling. Released on September 23 alongside Wireshark 4.4.19, the update is available as Windows and macOS installers and source code.

Wireshark is the world’s most widely used network protocol analyzer, supporting packet-level troubleshooting, security analysis, software development, and education. Because analysts routinely open traffic captures and files collected from untrusted environments, flaws in the application’s parsing and dissection components can create a direct workstation risk, not merely interrupt an investigation.

Wireshark 4.6.9 Released

The most significant issue is CVE-2026-96419, tracked as wnpa-sec-2026-106. A specially crafted configuration profile can crash Wireshark or potentially execute arbitrary code when a user is persuaded to import it. The flaw affects Wireshark 4.6.0 through 4.6.8, and the 4.4 branch from 4.4.0 through 4.4.18; fixes are included in 4.6.9 and 4.4.19.

Wireshark’s advisory says it is unaware of active exploitation. However, the required user interaction does not eliminate the danger: a malicious profile could be delivered through phishing, a shared analysis package, a support case, or an untrusted repository and presented as a legitimate troubleshooting configuration.

The remaining advisories cover crashes, excessive loops, memory leaks, and denial-of-service conditions triggered while processing malformed data. Affected components include the ZigBee ZCL, SCTP, SPDY, CSN.1, MBIM, Frame, RF4CE, TIFF, X11, IEEE 802.11, Catapult DCT2000, USB HID, and IEEE C37.118 Synchrophasor dissectors. Parsers for TTL, PEAK CAN TRC, Microsoft Network Monitor, and Toshiba captures are also affected, while another flaw can crash Sharkd.

Several defects can consume resources without immediately terminating the application. The TTL and TIFF issues cause infinite loops, Microsoft Network Monitor parsing can enter a large loop, the Synchrophasor dissector leaks memory, and USB HID processing combines an infinite loop with a memory leak. Crafted captures could therefore hang analysis, exhaust resources, or disrupt automated pipelines.

Beyond the 19 CVE-backed advisories, Wireshark 4.6.9 corrects multiple security-relevant bugs. These include a DICOM heap overwrite caused by a 32-bit length wrap, LBMC fragment reassembly and Bluetooth AVCTP integer overflows, an SMB object-export integer overflow, a PKCS12 null-pointer dereference, and a stack-based buffer overflow in etwdump when parsing crafted ETL files.

The release notes also identify two separately tracked remote-code-execution bugs involving LBMC fragment reassembly and LoRaWAN decryption. Other fixes address out-of-bounds reads, an uninitialized buffer pointer, excessive DICOM memory amplification, and incorrect handling of GREASE values during JA4 fingerprint calculation.

These corrections matter to SOC teams because parser reliability and fingerprint accuracy directly affect triage, detection engineering, and forensic conclusions.

No new protocols were added. Wireshark updated support for technologies including QUIC, SMB, OpenFlow, DICOM, LoRaWAN, IEEE 802.11, X11, ZigBee ZCL, and SPDY, while capture-file updates cover BLF, Network Monitor, pcapng, PEAK TRC, Toshiba, and TTL.

Organizations should upgrade immediately to Wireshark 4.6.9 or, if remaining on the older maintenance branch, 4.4.19 or later. Until updates are deployed, analysts should avoid importing profiles or opening capture files from unverified sources, isolate risky analysis in a sandbox or disposable virtual machine, and restrict automated processing privileges.

Administrators should check analyst endpoints, jump boxes, forensic workstations, and centrally managed capture appliances. Official packages are available from Wireshark’s download page, which lists 4.6.9 as the stable release.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link