Wireshark

Developer ToolsDesktop

The network protocol analyzer: live capture and deep inspection of hundreds of protocols.

Latest v4.4.18 · · Desktopby Wireshark FoundationWebsite

Release activity

Release activity — 14 releases across 5 days since Jun 3, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jun 3, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
MondayNo releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
TuesdayNo releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026
Wednesday2 releases on Jun 3, 20262 releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 20264 releases on Jul 8, 20262 releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 20264 releases on Aug 12, 2026
ThursdayNo releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026
FridayNo releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026
SaturdayNo releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026

14 releases since Jun 3, 2026, busiest day 4

Changelog

v4.4.19Pre-release

v4.4.19rc0

Tag: v4.4.19rc0

View originalPermalink
How v4.4.19 went
v4.6.9Pre-release

v4.6.9rc0

Tag: v4.6.9rc0

View originalPermalink
How v4.6.9 went

v4.4.18

Tag: v4.4.18

Security 20
  • Fix sharkd crash (wnpa-sec-2026-64)
  • Fix sharkd crash (wnpa-sec-2026-65)
  • Fix UMTS FP protocol dissector crash (wnpa-sec-2026-66)
  • Fix RDP protocol dissector crash (wnpa-sec-2026-67)
  • Fix dissection engine reassembly crash (wnpa-sec-2026-69)
  • Fix BUSMASTER file parser abnormal exit (wnpa-sec-2026-70)

Wireshark 4.4.18 Release Notes

What is Wireshark?

Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. Wireshark is hosted by the Wireshark Foundation, a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work! If you or your organization would like to contribute or become a sponsor, please visit wiresharkfoundation.org. If you use Wireshark professionally or you just want to learn more about protocol analysis, you should join us at SharkFest, the Wireshark developer and user conference. You can also become a Wireshark Certified Analyst! Official Wireshark training and certification are available from the Wireshark Foundation.

What’s New
Bug Fixes

The following vulnerabilities have been fixed:

  • wnpa-sec-2026-64 sharkd crash. Issue 21395.
  • wnpa-sec-2026-65 sharkd crash. Issue 21399.
  • wnpa-sec-2026-66 UMTS FP protocol dissector crash. Issue 21413.
  • wnpa-sec-2026-67 RDP protocol dissector crash. Issue 21396.
  • wnpa-sec-2026-69 Dissection engine reassembly crash. Issue 21423.
  • wnpa-sec-2026-70 BUSMASTER file parser abnormal exit. Issue 21435.
  • wnpa-sec-2026-71 Tektronix K12xx file parser crash. Issue 21414.
  • wnpa-sec-2026-72 ERF file parser crash. Issue 21415.
  • wnpa-sec-2026-73 Bluetooth Attribute Protocol dissector crash. Issue 21424.
  • wnpa-sec-2026-74 Catapult DCT2000 file parser crash. Issue 21427.
  • wnpa-sec-2026-75 C12.22 protocol dissector crash. Issue 21439.
  • wnpa-sec-2026-76 CMS protocol dissector crash. Issue 21446.
  • wnpa-sec-2026-77 H.245 protocol dissector crash. Issue 21447.
  • wnpa-sec-2026-78 Kerberos protocol dissector crash. Issue 21449.
  • wnpa-sec-2026-79 Bluetooth HFP Profile protocol dissector crash. Issue 21451.
  • wnpa-sec-2026-80 Bluetooth BR/EDR FHS protocol dissector crash. Issue 21452.
  • wnpa-sec-2026-81 3gpp phone log file parser crash. Issue 21454.
  • wnpa-sec-2026-83 CMS protocol dissector crash. Issue 21457, Issue 21458.
  • wnpa-sec-2026-84 Pcapng file parser crash. Issue 21460.
  • wnpa-sec-2026-85 SSH protocol dissector crash. Issue 21465.
  • wnpa-sec-2026-86 ESS protocol dissector crash. Issue 21467.
  • wnpa-sec-2026-87 X.509IF protocol dissector crash. Issue 21469. CVE-2026-xxx.
  • wnpa-sec-2026-88 RRC protocol dissector crash. Issue 21478.
  • wnpa-sec-2026-89 C12.22 protocol dissector crash. Issue 21480.
  • wnpa-sec-2026-91 Bluetooth AVRCP Profile protocol dissector crash. Issue 21488. The following bugs have been fixed:
  • Wireshark Version 4.6.6 - File Capture Properties is excessively slow and hangs Wireshark on Windows. Issue 21337.
  • Wireshark misdecodes S-NSSAI location validity information IE (5G NAS) Issue 21411.
  • Wireshark misdecodes NSAG information IE (5G NAS) Issue 21412.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-07-17-15393056954.pcap. Issue 21419.
  • Wireshark misdecodes UE security capability IE (5G NAS) Issue 21431.
  • Wireshark misdecodes Registration wait range IE (5G NAS) Issue 21432.
  • Wireshark misdecodes Extended CAG information IE (5G NAS) Issue 21433.
  • Stack buffer overflow in K12/RF5 writer. Issue 21436.
  • packet-knxip: Secure Wrapper size-offset causes NULL deref / SEGV when decrypting. Issue 21444.
  • wiretap/rtpdump: swapped caplen/len on truncated samples. Issue 21445.
  • Sniffer REC_HEADER2 error path over-reads stack buffer. Issue 21461.
  • Deep NetLog JSON nesting exhausts the native stack. Issue 21462.
  • androiddump signed btsnoop length causes global out-of-bounds read. Issue 21464.
  • Wireshark misdecodes SOR transparent container IE (5G NAS) Issue 21472.
  • Unbounded Daintree timestamp fraction causes signed integer overflow. Issue 21473.
  • Wireshark misdecodes SOR-CMCI of SOR transparent container IE (5G NAS) Issue 21477.
  • Wireshark misdecodes Service level AA container (5GSM NAS) Issue 21479.
New and Updated Features
New Protocol Support

There are no new protocols in this release.

Updated Protocol Support

BT ATT, BT AVRCP, BT BR/EDR RF, BT HFP, C12.22, CMS, ESS, FP, H.245, Kerberos, Rlogin, SSH, X.509AF, and X.509IF

New and Updated Capture File Support

3gpp phone log, Busmaster, Catapult DCT2000, Daintree SNA, Endace ERF, pcapng, RTPDump, Sniffer, and Tektronix K12xx

New and Updated File Format Decoding Support

There is no updated file format support in this release.

Prior Versions

Wireshark 4.4.17 included the following changes. See the release notes for details:

  • wnpa-sec-2026-52 Catapult DCT2000 protocol dissector crash. Issue 21270.
  • wnpa-sec-2026-54 FMP/NOTIFY protocol dissector large loop. Issue 21347.
  • wnpa-sec-2026-55 SSH protocol dissector crash. Issue 21378.
  • wnpa-sec-2026-57 IEEE 802.11 protocol dissector crash. Issue 21391.
  • wnpa-sec-2026-58 Z39.50 protocol dissector crash. Issue 21397.
  • wnpa-sec-2026-59 UMTS FP protocol dissector crash. Issue 21398.
  • wnpa-sec-2026-60 BLF file parser information disclosure. Issue 21361.
  • wnpa-sec-2026-61 Multiple protocol dissector infinite loops. Issue 21275, Issue 21277, Issue 21330, Issue 21383.
  • wnpa-sec-2026-62 DBS Etherwatch file parser crash. Issue 21352.
  • wnpa-sec-2026-63 Ciscodump extcap crash. Issue 21375.
  • Build failure with Qt 6.11 beta. Issue 20965.
  • BACapp: Error parsing you-are request. Issue 21260.
  • Fuzz job issue: fuzz-2026-05-24-14517548985.pcap. Issue 21272.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-06-07-14732586286.pcap. Issue 21331.
  • Memory leak in alp-sample1.pcap. Issue 21343.
  • Heap-Buffer-Overflow in Wireshark Logcat Parser. Issue 21346.
  • HEVC (H.265) dissector: bit_offset not advanced after sub_layer_hrd_parameters() causes false Malformed Packet. Issue 21362.
  • dfilter_compile_full: heap-buffer-overflow READ in ws_strptime on a time literal. Issue 21376.
  • Wireshark crashes with a HEAP_CORRUPTION error when using the last saved recent_common file. Issue 21379.
  • Fuzz job issue: fuzz-2026-06-30-15106674620.pcap. Issue 21381. Wireshark 4.4.16 included the following changes. See the release notes for details:
  • vwr: Read of uninitialized memory in pntoh16. Issue 16460.
  • vwr: Read of uninitialized memory in find_signature. Issue 16461.
  • Fuzz job issue: fuzz-2026-05-02-14184750352.pcap. Issue 21240.
  • ROHC NULL Write / Heap Corruption with uncompressed profile and large CID. Issue 21243.
  • Fuzz job crash: fuzz-2026-05-18-14414274873.pcap. Issue 21261. Wireshark 4.4.15 included the following changes. See the release notes for details:
  • wnpa-sec-2026-08 Monero dissector crash. Issue 21066. CVE-2026-5409.
  • wnpa-sec-2026-09 BT-DHT dissector crash. Issue 21067. CVE-2026-5408.
  • wnpa-sec-2026-10 FC-SWILS dissector crash. Issue 21070. CVE-2026-5406.
  • wnpa-sec-2026-11 SMB2 dissector infinite loop. Issue 21073. CVE-2026-5407.
  • wnpa-sec-2026-12 ICMPv6 dissector crash. Issue 21077. CVE-2026-5299.
  • wnpa-sec-2026-13 AFP dissector crash. Issue 21088. CVE-2026-5401.
  • wnpa-sec-2026-15 K12 RF5 file parser crash. Issue 21094. CVE-2026-5404.
  • wnpa-sec-2026-16 SBC codec crash and possible code execution. Issue 21103. CVE-2026-5403.
  • wnpa-sec-2026-17 RDP dissector crash and possible code execution. Issue 21105. CVE-2026-5405.
  • wnpa-sec-2026-18 AMR-NB codec crash. Issue 21111. CVE-2026-5654.
  • wnpa-sec-2026-20 iLBC audio codec crash. Issue 21113. CVE-2026-5657.
  • wnpa-sec-2026-21 Profile import crash and possible code execution. Issue 21115. CVE-2026-5656.
  • wnpa-sec-2026-22 DCP-ETSI protocol dissector crash. Issue 21122. CVE-2026-5653.
  • wnpa-sec-2026-23 BEEP protocol dissector crash. Issue 21120. CVE-2026-6538.
  • wnpa-sec-2026-24 ZigBee protocol dissector crash. Issue 21125. CVE-2026-6537.
  • wnpa-sec-2026-26 Dissection engine zlib decompression crash. Issue 21097, Issue 21098. CVE-2026-6535.
  • wnpa-sec-2026-27 USB HID protocol dissector infinite loop. Issue 21121. CVE-2026-6534.
  • wnpa-sec-2026-28 Dissection engine LZ77 decompression crash. Issue 21127. CVE-2026-6533.
  • wnpa-sec-2026-29 Kismet protocol dissector crash. Issue 21129, Issue 21128. CVE-2026-6532.
  • wnpa-sec-2026-30 SANE protocol dissector infinite loop. Issue 21139. CVE-2026-6531.
  • wnpa-sec-2026-31 DCP-ETSI protocol dissector crash. Issue 21144. CVE-2026-6530.
  • wnpa-sec-2026-32 iLBC audio codec crash. Issue 21145. CVE-2026-6529.
  • wnpa-sec-2026-34 ASN.1 PER protocol dissector crash. Issue 21149. CVE-2026-6527.
  • wnpa-sec-2026-37 MySQL protocol dissector crash. Issue 21172. CVE-2026-6524.
  • wnpa-sec-2026-38 GNW protocol dissector infinite loop. Issue 21177. CVE-2026-6523.
  • wnpa-sec-2026-39 OpenFlow v5 protocol dissector infinite loops. Issue 21182, Issue 21188. CVE-2026-6521.
  • wnpa-sec-2026-40 OpenFlow v6 protocol dissector infinite loop. Issue 21181. CVE-2026-6520.
  • wnpa-sec-2026-41 MBIM dissector infinite loop. Issue 21184. CVE-2026-6519.
  • wnpa-sec-2026-42 RPKI-Router protocol dissector infinite loop. Issue 21186. CVE-2026-6522.
  • wnpa-sec-2026-43 GSM RP protocol dissector crash. Issue 21189. CVE-2026-6870.
  • wnpa-sec-2026-44 WebSocket protocol dissector crash. Issue 21190. CVE-2026-6869.
  • wnpa-sec-2026-45 SMB2 protocol dissector crash. Issue 21191.
  • wnpa-sec-2026-46 HTTP protocol dissector crash. Issue 21185. CVE-2026-6868.
  • wnpa-sec-2026-47 Sharkd utility memory leak. Issue 21214.
  • wnpa-sec-2026-48 Sharkd utility crash. Issue 21206.
  • wnpa-sec-2026-49 Sharkd utility crash. Issue 21207.
  • wnpa-sec-2026-50 UDS protocol dissector infinite loop. Issue 21225.
  • Over large memory usage when uncompressing high compression ratio http payload. Issue 13779.
  • WSUG: Enabled Protocols dialog needs an update. Issue 20871.
  • SMB2 decryption keys in smb2_seskey_list are not loaded on restart. Issue 21036.
  • Fuzz job issue: fuzz-2026-03-01-13307044520.pcap. Issue 21049.
  • Window with a message for ssh_strict_fopen. Issue 21051.
  • Fuzz job crash: fuzz-2026-03-25-13637733472.pcap. Issue 21117.
  • dumpcap TCP@ section-header parsing remote heap corruption. Issue 21132.
  • On Windows, the Follow Stream feature output is shown in proportional font after zooming. Issue 21137.
  • RTP Streams dialog Time of Day inconsistent behavior. Issue 21138.
  • RF4CE NWK Dissector Heap Buffer Overflow (crash/OOB) Issue 21150.
  • NetXray/Sniffer Padding Integer Underflow. Issue 21152.
  • HTTP/2 ALTSVC/PRIORITY_UPDATE Frame Length Truncation (24-bit to 16-bit) Issue 21155.
  • Snort config parser 2 buffer overflows. Issue 21165.
  • ESP NULL Encryption Integer Underflow triggers Heap Overflow. Issue 21166.
  • Heap buffer overflow in ISO 8583 dissector bin2hex() Issue 21171.
  • wslua: NULL pointer dereference in get_dissector when passing an invalid GUID string to an FT_GUID table. Issue 21194.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-04-16-13947406035.pcap. Issue 21199.
  • Qt: Waterfall bars misisng in conversation overview when "limit to display filter" is active. Issue 21204.
  • text2pcap: heap-buffer-overflow in memmove when -P"dissector" payload exceeds reserved space. Issue 21208.
  • text2pcap : Stack overflow via unbounded "g_alloca" in regex "seqno" Issue 21209.
  • editcap: --novlan integer underflow in sll_remove_vlan_info causes denial of service on short SLL captures. Issue 21210.
  • NAS-5GS - Mapping issue between IEI 0x7B and "S-NSSAI location validity information" IE. Issue 21218.
  • RTP-MIDI dissector reports incorrect value for MTC Quarter Frame data. Issue 21231. Wireshark 4.4.14 included the following changes. See the release notes for details:
  • wnpa-sec-2026-05 USB HID dissector memory exhaustion. Issue 20972. CVE-2026-3201.
  • wnpa-sec-2026-07 RF4CE Profile dissector crash. Issue 21009. CVE-2026-3203.
  • Bug in decoding 5G NAS message - Extended CAG information list IE. Issue 20946.
  • PQC signature algorithm not reported in signature_algorithms. Issue 20953.
  • Unexpected JA4 ALPN values when space characters sent. Issue 20966.
  • Expert Info seems to have quadratic performance (gets slower and slower) Issue 20970. …
View originalPermalink
How v4.4.18 went

v4.6.8

Tag: v4.6.8

Security 20
  • Fix sharkd crash
  • Fix UMTS FP protocol dissector crash
  • Fix RDP protocol dissector crash
  • Fix TTX Logger file parser crash
  • Fix dissection engine reassembly crash
  • Fix BUSMASTER file parser abnormal exit

Wireshark 4.6.8 Release Notes

What is Wireshark?

Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. Wireshark is hosted by the Wireshark Foundation, a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work. If you or your organization would like to contribute or become a sponsor, please visit wiresharkfoundation.org. If you use Wireshark professionally or you just want to learn more about protocol analysis, you should join us at SharkFest, the Wireshark developer and user conference. You can also become a Wireshark Certified Analyst! Official Wireshark training and certification are available from the Wireshark Foundation.

What’s New
Bug Fixes

The following vulnerabilities have been fixed:

  • wnpa-sec-2026-64 sharkd crash. Issue 21395.
  • wnpa-sec-2026-65 sharkd crash. Issue 21399.
  • wnpa-sec-2026-66 UMTS FP protocol dissector crash. Issue 21413.
  • wnpa-sec-2026-67 RDP protocol dissector crash. Issue 21396.
  • wnpa-sec-2026-68 TTX Logger file parser crash. Issue 21389.
  • wnpa-sec-2026-69 Dissection engine reassembly crash. Issue 21423.
  • wnpa-sec-2026-70 BUSMASTER file parser abnormal exit. Issue 21435.
  • wnpa-sec-2026-71 Tektronix K12xx file parser crash. Issue 21414.
  • wnpa-sec-2026-72 ERF file parser crash. Issue 21415.
  • wnpa-sec-2026-73 Bluetooth Attribute Protocol dissector crash. Issue 21424.
  • wnpa-sec-2026-74 Catapult DCT2000 file parser crash. Issue 21427.
  • wnpa-sec-2026-75 C12.22 protocol dissector crash. Issue 21439.
  • wnpa-sec-2026-76 CMS protocol dissector crash. Issue 21446.
  • wnpa-sec-2026-77 H.245 protocol dissector crash. Issue 21447.
  • wnpa-sec-2026-78 Kerberos protocol dissector crash. Issue 21449.
  • wnpa-sec-2026-79 Bluetooth HFP Profile protocol dissector crash. Issue 21451.
  • wnpa-sec-2026-80 Bluetooth BR/EDR FHS protocol dissector crash. Issue 21452.
  • wnpa-sec-2026-81 3gpp phone log file parser crash. Issue 21454.
  • wnpa-sec-2026-82 Ixia IxVeriWave and Vector Informatik BLF file parser crashes on Windows. Issue 21455.
  • wnpa-sec-2026-83 CMS protocol dissector crash. Issue 21457, Issue 21458.
  • wnpa-sec-2026-84 Pcapng file parser crash. Issue 21460.
  • wnpa-sec-2026-85 SSH protocol dissector crash. Issue 21465.
  • wnpa-sec-2026-86 ESS protocol dissector crash. Issue 21467.
  • wnpa-sec-2026-87 X.509IF protocol dissector crash. Issue 21469. CVE-2026-xxx.
  • wnpa-sec-2026-88 RRC protocol dissector crash. Issue 21478.
  • wnpa-sec-2026-89 C12.22 protocol dissector crash. Issue 21480.
  • wnpa-sec-2026-90 Gammu DCT3 trace file parser crash. Issue 21475.
  • wnpa-sec-2026-91 Bluetooth AVRCP Profile protocol dissector crash. Issue 21488. The following bugs have been fixed:
  • Fuzz job crash: randpkt-2026-05-22-14496207576.pcap. Issue 21266.
  • Wireshark Version 4.6.6 - File Capture Properties is excessively slow and hangs Wireshark on Windows. Issue 21337.
  • TCP Preference 'Analyze TCP sequence numbers' SEGFAULTs when toggled. Issue 21380.
  • Wireshark misdecodes S-NSSAI location validity information IE (5G NAS) Issue 21411.
  • Wireshark misdecodes NSAG information IE (5G NAS) Issue 21412.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-07-17-15393056954.pcap. Issue 21419.
  • Wireshark misdecodes UE security capability IE (5G NAS) Issue 21431.
  • Wireshark misdecodes Registration wait range IE (5G NAS) Issue 21432.
  • Wireshark misdecodes Extended CAG information IE (5G NAS) Issue 21433.
  • Stack buffer overflow in K12/RF5 writer. Issue 21436.
  • Security issues fixed in 4.6.8 and 4.4.18 Tracker. Issue 21437.
  • BLF writer out-of-bounds read on truncated VLAN-tagged Ethernet frames. Issue 21441.
  • DLMS/COSEM compact-array TypeDescription recursion bypass can exhaust the stack. Issue 21442.
  • packet-knxip: Secure Wrapper size-offset causes NULL deref / SEGV when decrypting. Issue 21444.
  • wiretap/rtpdump: swapped caplen/len on truncated samples. Issue 21445.
  • H.245 returnedFunction nested GenericMessage dereferences NULL packet state. Issue 21447.
  • X.509 export-object tap dereferences missing certificate subject. Issue 21448.
  • Sniffer REC_HEADER2 error path over-reads stack buffer. Issue 21461.
  • Deep NetLog JSON nesting exhausts the native stack. Issue 21462.
  • androiddump signed btsnoop length causes global out-of-bounds read. Issue 21464.
  • ERF writer underflows payload length for tiny truncated packets. Issue 21466.
  • Wireshark misdecodes SOR transparent container IE (5G NAS) Issue 21472.
  • Unbounded Daintree timestamp fraction causes signed integer overflow. Issue 21473.
  • Wireshark misdecodes SOR-CMCI of SOR transparent container IE (5G NAS) Issue 21477.
  • Wireshark misdecodes Service level AA container (5GSM NAS) Issue 21479.
New and Updated Features
New Protocol Support

There are no new protocols in this release.

Updated Protocol Support

ANSI_TCAP, ASN.1 BER, ASTERIX, BT ATT, BT AVRCP, BT BR/EDR RF, BT HFP, C12.22, CIGI, CMS, COSEM, EBHSCR, ESS, FP, GSM SIM, GTPv2, H.245, Kerberos, KNX/IP, LBMSRS, NAS-5GS, RELOAD, Rlogin, RRC, SSH, X.509AF, and X.509IF

New and Updated Capture File Support

3gpp phone log, BLF, Busmaster, Catapult DCT2000, Daintree SNA, Endace ERF, Gammu DCT3, pcapng, RTPDump, Sniffer, Tektronix K12xx, and TTTech Computertechnik TTL

New and Updated File Format Decoding Support

There is no new or updated file format support in this release.

Plugin Development Changes

On UN*X systems (excluding macOS when running from an app bundle, as with the official installer) extcap binaries are now searched for under the libexec directory by default, e.g., /usr/libexec/wireshark/extcap instead of /usr/lib64/wireshark/extcap or similar. This is the customary place for helper binaries, which as opposed to libraries do not need multiarch support. The location can be overridden via the environment variable WIRESHARK_EXTCAP_DIR. The extcap binaries shipped with Wireshark are installed in the new location, but third party extcaps may need packaging changes. This change was effective in version 4.6.0, but was not explicitly noted in the release notes previously. Note that some distributions do not use a libexec directory, such as Alpine Linux, which does not have multilib support. On such systems extcap binaries should be in the same location as before.

Prior Versions
Wireshark 4.6.7 included the following changes.
  • wnpa-sec-2026-52 Catapult DCT2000 protocol dissector crash. Issue 21270.
  • wnpa-sec-2026-53 pcapng file parser crash. Issue 21285.
  • wnpa-sec-2026-54 FMP/NOTIFY protocol dissector large loop. Issue 21347.
  • wnpa-sec-2026-55 SSH protocol dissector crash. Issue 21378.
  • wnpa-sec-2026-56 TLS ECH decryption crash. Issue 21390.
  • wnpa-sec-2026-57 IEEE 802.11 protocol dissector crash. Issue 21391.
  • wnpa-sec-2026-58 Z39.50 protocol dissector crash. Issue 21397.
  • wnpa-sec-2026-59 UMTS FP protocol dissector crash. Issue 21398.
  • wnpa-sec-2026-60 BLF file parser information disclosure. Issue 21361.
  • wnpa-sec-2026-61 Multiple protocol dissector infinite loops. Issue 21275, Issue 21277, Issue 21330, Issue 21383.
  • wnpa-sec-2026-62 DBS Etherwatch file parser crash. Issue 21352.
  • wnpa-sec-2026-63 Ciscodump extcap crash. Issue 21375.
  • Wireshark appears in German when the system language is Dutch. Issue 20347.
  • Qt: Capture filter combo box does not enforce minimum size or expanding size policy. Issue 21080.
  • BACapp: Error parsing you-are request. Issue 21260.
  • Use-After-Free in Ethernet POWERLINK (EPL) Dissector during profile loading error path. Issue 21267.
  • Sponsor slides are not properly shown. Issue 21268.
  • Buffer overlow/segfault in Catapult DCT2000 dissector via not check no_ddi_entries in header. Issue 21270.
  • Fuzz job issue: fuzz-2026-05-24-14517548985.pcap. Issue 21272.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-06-07-14732586286.pcap. Issue 21331.
  • Memory leak in alp-sample1.pcap. Issue 21343.
  • Memory leak in nspi.pcap. Issue 21344.
  • Heap-Buffer-Overflow in Wireshark Logcat Parser. Issue 21346.
  • IPv6 Ping from Debian (among others) is dissected as "HiPerConTracer" Issue 21349.
  • HEVC (H.265) dissector: bit_offset not advanced after sub_layer_hrd_parameters() causes false Malformed Packet. Issue 21362.
  • dfilter_compile_full: heap-buffer-overflow READ in ws_strptime on a time literal. Issue 21376.
  • Wireshark crashes with a HEAP_CORRUPTION error when using the last saved recent_common file. Issue 21379.
  • Fuzz job issue: fuzz-2026-06-30-15106674620.pcap. Issue 21381.
Wireshark 4.6.6 included the following changes.

See the release notes for details:

  • wnpa-sec-2026-51 ROHC protocol dissector crash. Issue 21243.
  • Wireshark crashes when run under Visual Studio on Windows. Work item 24787.
  • Welcome page slide preferences are now available in the preferences window.
  • vwr: Read of uninitialized memory in pntoh16. Issue 16460.
  • vwr: Read of uninitialized memory in find_signature. Issue 16461.
  • Upgrades on Windows do not retain existing optional features unless explicitly requested, resulting in accidental removal of features. Issue 18925.
  • Wireshark.exe version 4.6.5 is twice as large as version 4.6.4. Issue 21233.
  • MACsec dissector global-buffer-overflow. Issue 21235.
  • Wireshark 4.6.5 does not run on Windows 10 version 1809 (including Server 2019 and some LTSC versions) Issue 21237.
  • Fuzz job issue: fuzz-2026-05-02-14184750352.pcap. Issue 21240.
  • packet-bacapp: rename aurth-request to auth-request. Issue 21246.
  • Fuzz job issue: randpkt-2026-05-10-14293434231.pcap. Issue 21253.
Wireshark 4.6.5 included the following changes.

See the release notes for details:

  • wnpa-sec-2026-08 Monero dissector crash. Issue 21066. CVE-2026-5409.
  • wnpa-sec-2026-09 BT-DHT dissector crash. Issue 21067. CVE-2026-5408.
  • wnpa-sec-2026-10 FC-SWILS dissector crash. Issue 21070. CVE-2026-5406.
  • wnpa-sec-2026-11 SMB2 dissector infinite loop. Issue 21073. CVE-2026-5407.
  • wnpa-sec-2026-12 ICMPv6 dissector crash. Issue 21077. CVE-2026-5299.
  • wnpa-sec-2026-13 AFP dissector crash. Issue 21088. CVE-2026-5401.
  • wnpa-sec-2026-14 TLS dissector crash and possible code execution. Issue 21090. CVE-2026-5402.
  • wnpa-sec-2026-15 K12 RF5 file parser crash. Issue 21094. CVE-2026-5404.
  • wnpa-sec-2026-16 SBC codec crash and possible code execution. Issue 21103. CVE-2026-5403.
  • wnpa-sec-2026-17 RDP dissector crash and possible code execution. Issue 21105. CVE-2026-5405.
  • wnpa-sec-2026-18 AMR-NB codec crash. Issue 21111. CVE-2026-5654.
  • wnpa-sec-2026-19 SDP dissector crash. Issue 2111. CVE-2026-5655.
  • wnpa-sec-2026-20 iLBC audio codec crash. Issue 21113. CVE-2026-5657.
  • wnpa-sec-2026-21 Profile import crash and possible code execution. Issue 21115. CVE-2026-5656.
  • wnpa-sec-2026-22 DCP-ETSI protocol dissector crash. Issue 21122. CVE-2026-5653.
  • wnpa-sec-2026-23 BEEP protocol dissector crash. Issue 21120. CVE-2026-6538.
  • wnpa-sec-2026-24 ZigBee protocol dissector crash. Issue 21125. CVE-2026-6537.
  • wnpa-sec-2026-25 DLMS/COSEM protcol dissector infinite loop. Issue 21065. CVE-2026-6536.
  • wnpa-sec-2026-26 Dissection engine zlib decompression crash. Issue 21097, Issue 21098. CVE-2026-6535.
  • wnpa-sec-2026-27 USB HID protocol dissector infinite loop. Issue 21121. CVE-2026-6534.
  • wnpa-sec-2026-28 Dissection engine LZ77 decompression crash. Issue 21127. CVE-2026-6533.
  • wnpa-sec-2026-29 Kismet protocol dissector crash. Issue 21129, Issue 21128. CVE-2026-6532.
  • wnpa-sec-2026-30 SANE protocol dissector infinite loop. Issue 21139. CVE-2026-6531.
  • wnpa-sec-2026-31 DCP-ETSI protocol dissector crash. Issue 21144. CVE-2026-6530.
  • wnpa-sec-2026-32 iLBC audio codec crash. Issue 21145. CVE-2026-6529.
  • wnpa-sec-2026-33 TLS dissector infinite loop. Issue 21151. CVE-2026-6528.
  • wnpa-sec-2026-34 ASN.1 PER protocol dissector crash. Issue 21149. CVE-2026-6527.
  • wnpa-sec-2026-35 RTSP protocol dissector crash. Issue 21173. CVE-2026-6526. …
View originalPermalink
How v4.6.8 went
v4.7.3Pre-release

v4.7.3rc0

Tag: v4.7.3rc0

View originalPermalink
How v4.7.3 went
v4.4.18Pre-release

v4.4.18rc0

Tag: v4.4.18rc0

View originalPermalink
How v4.4.18 went
v4.6.8Pre-release

v4.6.8rc0

Tag: v4.6.8rc0

View originalPermalink
How v4.6.8 went

v4.4.17

Tag: v4.4.17

Changed 2
  • Windows installers now ship with Qt 6.7.3 instead of Qt 6.5.3
  • Windows installers are now built with Visual Studio 2026
Fixed 8
  • Fixed build failure with Qt 6.11 beta
  • Fixed BACapp error parsing you-are request
  • Fixed UTF-8 encoding issue in fuzzing
  • Fixed memory leak in packet capture file
  • Fixed heap-buffer-overflow in Wireshark Logcat Parser
  • Fixed HEVC (H.265) dissector bit_offset advancement after sub_layer_hrd_parameters() causing false Malformed Packet
  • Fixed heap-buffer-overflow in dfilter_compile_full with time literal
  • Fixed Wireshark crash with HEAP_CORRUPTION error when using last saved recent_common file
Security 10
  • Fixed Catapult DCT2000 protocol dissector crash
  • Fixed FMP/NOTIFY protocol dissector large loop
  • Fixed SSH protocol dissector crash
  • Fixed IEEE 802.11 protocol dissector crash
  • Fixed Z39.50 protocol dissector crash
  • Fixed UMTS FP protocol dissector crash

Wireshark 4.4.17 Release Notes

What is Wireshark?

Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. Wireshark is hosted by the Wireshark Foundation, a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work! If you or your organization would like to contribute or become a sponsor, please visit wiresharkfoundation.org.

What’s New
Bug Fixes

The following vulnerabilities have been fixed:

  • wnpa-sec-2026-52 Catapult DCT2000 protocol dissector crash. Issue 21270.
  • wnpa-sec-2026-54 FMP/NOTIFY protocol dissector large loop. Issue 21347.
  • wnpa-sec-2026-55 SSH protocol dissector crash. Issue 21378.
  • wnpa-sec-2026-57 IEEE 802.11 protocol dissector crash. Issue 21391.
  • wnpa-sec-2026-58 Z39.50 protocol dissector crash. Issue 21397.
  • wnpa-sec-2026-59 UMTS FP protocol dissector crash. Issue 21398.
  • wnpa-sec-2026-60 BLF file parser information disclosure. Issue 21361.
  • wnpa-sec-2026-61 Multiple protocol dissector infinite loops. Issue 21275, Issue 21277, Issue 21330, Issue 21383.
  • wnpa-sec-2026-62 DBS Etherwatch file parser crash. Issue 21352.
  • wnpa-sec-2026-63 Ciscodump extcap crash. Issue 21375. The following bugs have been fixed:
  • Build failure with Qt 6.11 beta. Issue 20965.
  • BACapp: Error parsing you-are request. Issue 21260.
  • Fuzz job issue: fuzz-2026-05-24-14517548985.pcap. Issue 21272.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-06-07-14732586286.pcap. Issue 21331.
  • Memory leak in alp-sample1.pcap. Issue 21343.
  • Heap-Buffer-Overflow in Wireshark Logcat Parser. Issue 21346.
  • HEVC (H.265) dissector: bit_offset not advanced after sub_layer_hrd_parameters() causes false Malformed Packet. Issue 21362.
  • dfilter_compile_full: heap-buffer-overflow READ in ws_strptime on a time literal. Issue 21376.
  • Wireshark crashes with a HEAP_CORRUPTION error when using the last saved recent_common file. Issue 21379.
  • Fuzz job issue: fuzz-2026-06-30-15106674620.pcap. Issue 21381.
New and Updated Features
  • The Windows installers now ship with Qt 6.7.3. They previously shipped with Qt 6.5.3.
  • The Windows installers are now built with Visual Studio 2026.
New Protocol Support

There are no new protocols in this release.

Updated Protocol Support

ALC, BACapp, Catapult DCT2000, COTP, CSN.1, DNS, eDonkey, FC ELS, FMP/NOTIFY, H.265, IEEE 802.11, LLS, MEGACO, MIH, MPEG DSM-CC, RELOAD, SSH, UMTS FP, WOWW, and Z39.50

New and Updated Capture File Support

Android Logcat, BLF, and DBS Etherwatch

New and Updated File Format Decoding Support

There is no updated file format support in this release.

Prior Versions

Wireshark 4.4.16 included the following changes. See the release notes for details:

  • vwr: Read of uninitialized memory in pntoh16. Issue 16460.
  • vwr: Read of uninitialized memory in find_signature. Issue 16461.
  • Fuzz job issue: fuzz-2026-05-02-14184750352.pcap. Issue 21240.
  • ROHC NULL Write / Heap Corruption with uncompressed profile and large CID. Issue 21243.
  • Fuzz job crash: fuzz-2026-05-18-14414274873.pcap. Issue 21261. Wireshark 4.4.15 included the following changes. See the release notes for details:
  • wnpa-sec-2026-08 Monero dissector crash. Issue 21066. CVE-2026-5409.
  • wnpa-sec-2026-09 BT-DHT dissector crash. Issue 21067. CVE-2026-5408.
  • wnpa-sec-2026-10 FC-SWILS dissector crash. Issue 21070. CVE-2026-5406.
  • wnpa-sec-2026-11 SMB2 dissector infinite loop. Issue 21073. CVE-2026-5407.
  • wnpa-sec-2026-12 ICMPv6 dissector crash. Issue 21077. CVE-2026-5299.
  • wnpa-sec-2026-13 AFP dissector crash. Issue 21088. CVE-2026-5401.
  • wnpa-sec-2026-15 K12 RF5 file parser crash. Issue 21094. CVE-2026-5404.
  • wnpa-sec-2026-16 SBC codec crash and possible code execution. Issue 21103. CVE-2026-5403.
  • wnpa-sec-2026-17 RDP dissector crash and possible code execution. Issue 21105. CVE-2026-5405.
  • wnpa-sec-2026-18 AMR-NB codec crash. Issue 21111. CVE-2026-5654.
  • wnpa-sec-2026-20 iLBC audio codec crash. Issue 21113. CVE-2026-5657.
  • wnpa-sec-2026-21 Profile import crash and possible code execution. Issue 21115. CVE-2026-5656.
  • wnpa-sec-2026-22 DCP-ETSI protocol dissector crash. Issue 21122. CVE-2026-5653.
  • wnpa-sec-2026-23 BEEP protocol dissector crash. Issue 21120. CVE-2026-6538.
  • wnpa-sec-2026-24 ZigBee protocol dissector crash. Issue 21125. CVE-2026-6537.
  • wnpa-sec-2026-26 Dissection engine zlib decompression crash. Issue 21097, Issue 21098. CVE-2026-6535.
  • wnpa-sec-2026-27 USB HID protocol dissector infinite loop. Issue 21121. CVE-2026-6534.
  • wnpa-sec-2026-28 Dissection engine LZ77 decompression crash. Issue 21127. CVE-2026-6533.
  • wnpa-sec-2026-29 Kismet protocol dissector crash. Issue 21129, Issue 21128. CVE-2026-6532.
  • wnpa-sec-2026-30 SANE protocol dissector infinite loop. Issue 21139. CVE-2026-6531.
  • wnpa-sec-2026-31 DCP-ETSI protocol dissector crash. Issue 21144. CVE-2026-6530.
  • wnpa-sec-2026-32 iLBC audio codec crash. Issue 21145. CVE-2026-6529.
  • wnpa-sec-2026-34 ASN.1 PER protocol dissector crash. Issue 21149. CVE-2026-6527.
  • wnpa-sec-2026-37 MySQL protocol dissector crash. Issue 21172. CVE-2026-6524.
  • wnpa-sec-2026-38 GNW protocol dissector infinite loop. Issue 21177. CVE-2026-6523.
  • wnpa-sec-2026-39 OpenFlow v5 protocol dissector infinite loops. Issue 21182, Issue 21188. CVE-2026-6521.
  • wnpa-sec-2026-40 OpenFlow v6 protocol dissector infinite loop. Issue 21181. CVE-2026-6520.
  • wnpa-sec-2026-41 MBIM dissector infinite loop. Issue 21184. CVE-2026-6519.
  • wnpa-sec-2026-42 RPKI-Router protocol dissector infinite loop. Issue 21186. CVE-2026-6522.
  • wnpa-sec-2026-43 GSM RP protocol dissector crash. Issue 21189. CVE-2026-6870.
  • wnpa-sec-2026-44 WebSocket protocol dissector crash. Issue 21190. CVE-2026-6869.
  • wnpa-sec-2026-45 SMB2 protocol dissector crash. Issue 21191.
  • wnpa-sec-2026-46 HTTP protocol dissector crash. Issue 21185. CVE-2026-6868.
  • wnpa-sec-2026-47 Sharkd utility memory leak. Issue 21214.
  • wnpa-sec-2026-48 Sharkd utility crash. Issue 21206.
  • wnpa-sec-2026-49 Sharkd utility crash. Issue 21207.
  • wnpa-sec-2026-50 UDS protocol dissector infinite loop. Issue 21225.
  • Over large memory usage when uncompressing high compression ratio http payload. Issue 13779.
  • WSUG: Enabled Protocols dialog needs an update. Issue 20871.
  • SMB2 decryption keys in smb2_seskey_list are not loaded on restart. Issue 21036.
  • Fuzz job issue: fuzz-2026-03-01-13307044520.pcap. Issue 21049.
  • Window with a message for ssh_strict_fopen. Issue 21051.
  • Fuzz job crash: fuzz-2026-03-25-13637733472.pcap. Issue 21117.
  • dumpcap TCP@ section-header parsing remote heap corruption. Issue 21132.
  • On Windows, the Follow Stream feature output is shown in proportional font after zooming. Issue 21137.
  • RTP Streams dialog Time of Day inconsistent behavior. Issue 21138.
  • RF4CE NWK Dissector Heap Buffer Overflow (crash/OOB) Issue 21150.
  • NetXray/Sniffer Padding Integer Underflow. Issue 21152.
  • HTTP/2 ALTSVC/PRIORITY_UPDATE Frame Length Truncation (24-bit to 16-bit) Issue 21155.
  • Snort config parser 2 buffer overflows. Issue 21165.
  • ESP NULL Encryption Integer Underflow triggers Heap Overflow. Issue 21166.
  • Heap buffer overflow in ISO 8583 dissector bin2hex() Issue 21171.
  • wslua: NULL pointer dereference in get_dissector when passing an invalid GUID string to an FT_GUID table. Issue 21194.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-04-16-13947406035.pcap. Issue 21199.
  • Qt: Waterfall bars misisng in conversation overview when "limit to display filter" is active. Issue 21204.
  • text2pcap: heap-buffer-overflow in memmove when -P"dissector" payload exceeds reserved space. Issue 21208.
  • text2pcap : Stack overflow via unbounded "g_alloca" in regex "seqno" Issue 21209.
  • editcap: --novlan integer underflow in sll_remove_vlan_info causes denial of service on short SLL captures. Issue 21210.
  • NAS-5GS - Mapping issue between IEI 0x7B and "S-NSSAI location validity information" IE. Issue 21218.
  • RTP-MIDI dissector reports incorrect value for MTC Quarter Frame data. Issue 21231. Wireshark 4.4.14 included the following changes. See the release notes for details:
  • wnpa-sec-2026-05 USB HID dissector memory exhaustion. Issue 20972. CVE-2026-3201.
  • wnpa-sec-2026-07 RF4CE Profile dissector crash. Issue 21009. CVE-2026-3203.
  • Bug in decoding 5G NAS message - Extended CAG information list IE. Issue 20946.
  • PQC signature algorithm not reported in signature_algorithms. Issue 20953.
  • Unexpected JA4 ALPN values when space characters sent. Issue 20966.
  • Expert Info seems to have quadratic performance (gets slower and slower) Issue 20970.
  • USB-HID: Resource exhaustion in parse_report_descriptor() due to missing array size limit. Issue 20972.
  • Fuzz job crash: fuzz-2026-02-01-12944805400.pcap [Zigbee Direct Tunneling Zigbee NWK PDUs NULL hash table] Issue 20977.
  • RDM status in Output Status (GoodOutputB) field incorrectly decoded in Art-Net PollReply dissector. Issue 20980.
  • TDS dissector desynchronizes on RPC DATENTYPE (0x28) due to incorrect expectation of TYPE_VARLEN (MaxLen) Issue 21001.
  • Only first HTTP POST is parsed inside SOCKS with "Decode As" Issue 21006.
  • Fuzz job crash: fuzz-2026-02-06-13021968622.pcap. Issue 21009.
  • New Diameter RAT-Types in TS 29.212 not decoded. Issue 21012. Wireshark 4.4.13 included the following changes. See the release notes for details:
  • wnpa-sec-2026-01 BLF file parser crash. Issue 20880.
  • wnpa-sec-2026-02 IEEE 802.11 dissector crash. Issue 20939.
  • wnpa-sec-2026-03 SOME/IP-SD dissector crash. Issue 20945. Wireshark 4.4.12 included the following changes. See the release notes for details:
  • wnpa-sec-2025-07 HTTP3 dissector crash. Issue 20860. CVE-2025-13945.
  • wnpa-sec-2025-08 MEGACO dissector infinite loop. Issue 20884. CVE-2025-13945.
  • ws_base32_decode should be named *_encode ? Issue 20754.
  • Stack buffer overflow in wiretap/ber.c (ber_open) Issue 20878.
  • Fuzz job crash: fuzz-2025-11-30-12266121180.pcap. Issue 20883.
  • Missing data in pinfo→cinfo in HomePlug message CM_ATTEN_CHAR.IND. Issue 20893. Wireshark 4.4.11 included the following changes. See the release notes for details:
  • wnpa-sec-2025-06 Kafka dissector crash. Issue 20823.
  • L2CAP dissector doesn’t understand retransmission mode. Issue 2241.
  • DNS HIP dissector labels PK algorithm as HIT length. Issue 20768.
  • TLS Abbreviated Handshake Using New Session Ticket. Issue 20802.
  • Apply As Filter for field with FT_NONE and BASE_NONE for a single byte does not use the hex value. Issue 20818.
  • TCP dissector creates invalid packet diagram. Issue 20820.
  • Support UTF-16 strings in the IsoBus dissector for the string operations. Issue 20845.
  • Fuzz job issue: fuzz-2025-11-12-12064814316.pcap. Issue 20852. Wireshark 4.4.10 included the following changes. See the release notes for details:
  • Using wslog parameters in command line applications leads to freeing invalid memory. Issue 20500.
  • On macOS a lower resolution Wireshark icon is displayed in the App Switcher and Launchpad. sbug20544.
  • Fuzz job crash: fuzz-2025-08-06-10932469456.pcap. Issue 20666.
  • Encoding on NAS5GS- NASDL Transport Message-Multiple Container contains inconsistencies. wsbuglink:20679].
  • Bad resolver in Delegated Credential (RFC 9345) of TLS 1.3 CertificateRequest message. wsbuglink:20728].
  • Fuzz job UTF-8 encoding issue: fuzz-2025-10-03-11586692659.pcap. Issue 20744. Wireshark 4.4.9 included the following changes. See the release notes for details:
  • RDM Product Detail List ID Disect incorrect. Issue 20612.
  • SCCP LUDT segmentation decoding fails. Issue 20647.
  • Ciscodump fails to start capture on Cisco IOS. Issue 20655.
  • [BACnet] WritePropertyMultiple closing context tag 1 not showing. Issue 20665.
  • Bug in LZ77 decoder; reads a 16-bit length when it should read a 32-bit length. Issue 20671. Wireshark 4.4.8 included the following changes. See the release notes for details: …
View originalPermalink
How v4.4.17 went

v4.6.7

Tag: v4.6.7

Changed 1
  • Build Windows installers with Visual Studio 2026
Fixed 7
  • Fix Wireshark appearing in German when the system language is Dutch
  • Fix Qt capture filter combo box not enforcing minimum size or expanding size policy
  • Fix BACapp error parsing you-are request
  • Fix use-after-free in Ethernet POWERLINK (EPL) dissector during profile loading error path
  • Fix sponsor slides not being properly shown
  • Fix IPv6 ping from Debian being dissected as HiPerConTracer
  • Fix HEVC (H.265) dissector bit_offset not advanced after sub_layer_hrd_parameters causing false malformed packet
Security 12
  • Fix Catapult DCT2000 protocol dissector crash
  • Fix pcapng file parser crash
  • Fix FMP/NOTIFY protocol dissector large loop
  • Fix SSH protocol dissector crash
  • Fix TLS ECH decryption crash
  • Fix IEEE 802.11 protocol dissector crash

Wireshark 4.6.7 Release Notes

What is Wireshark?

Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. Wireshark is hosted by the Wireshark Foundation, a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work. If you or your organization would like to contribute or become a sponsor, please visit wiresharkfoundation.org. If you use Wireshark professionally or you just want to learn more about protocol analysis, you should join us at SharkFest, the Wireshark developer and user conference. You can also become a Wireshark Certified Analyst! Official Wireshark training and certification are available from the Wireshark Foundation.

What’s New
Bug Fixes

The following vulnerabilities have been fixed:

  • wnpa-sec-2026-52 Catapult DCT2000 protocol dissector crash. Issue 21270.
  • wnpa-sec-2026-53 pcapng file parser crash. Issue 21285.
  • wnpa-sec-2026-54 FMP/NOTIFY protocol dissector large loop. Issue 21347.
  • wnpa-sec-2026-55 SSH protocol dissector crash. Issue 21378.
  • wnpa-sec-2026-56 TLS ECH decryption crash. Issue 21390.
  • wnpa-sec-2026-57 IEEE 802.11 protocol dissector crash. Issue 21391.
  • wnpa-sec-2026-58 Z39.50 protocol dissector crash. Issue 21397.
  • wnpa-sec-2026-59 UMTS FP protocol dissector crash. Issue 21398.
  • wnpa-sec-2026-60 BLF file parser information disclosure. Issue 21361.
  • wnpa-sec-2026-61 Multiple protocol dissector infinite loops. Issue 21275, Issue 21277, Issue 21330, Issue 21383.
  • wnpa-sec-2026-62 DBS Etherwatch file parser crash. Issue 21352.
  • wnpa-sec-2026-63 Ciscodump extcap crash. Issue 21375. The following bugs have been fixed:
  • Wireshark appears in German when the system language is Dutch. Issue 20347.
  • Qt: Capture filter combo box does not enforce minimum size or expanding size policy. Issue 21080.
  • BACapp: Error parsing you-are request. Issue 21260.
  • Use-After-Free in Ethernet POWERLINK (EPL) Dissector during profile loading error path. Issue 21267.
  • Sponsor slides are not properly shown. Issue 21268.
  • Buffer overlow/segfault in Catapult DCT2000 dissector via not check no_ddi_entries in header. Issue 21270.
  • Fuzz job issue: fuzz-2026-05-24-14517548985.pcap. Issue 21272.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-06-07-14732586286.pcap. Issue 21331.
  • Memory leak in alp-sample1.pcap. Issue 21343.
  • Memory leak in nspi.pcap. Issue 21344.
  • Heap-Buffer-Overflow in Wireshark Logcat Parser. Issue 21346.
  • IPv6 Ping from Debian (among others) is dissected as "HiPerConTracer" Issue 21349.
  • HEVC (H.265) dissector: bit_offset not advanced after sub_layer_hrd_parameters() causes false Malformed Packet. Issue 21362.
  • dfilter_compile_full: heap-buffer-overflow READ in ws_strptime on a time literal. Issue 21376.
  • Wireshark crashes with a HEAP_CORRUPTION error when using the last saved recent_common file. Issue 21379.
  • Fuzz job issue: fuzz-2026-06-30-15106674620.pcap. Issue 21381.
New and Updated Features
  • The Windows installers are now built with Visual Studio 2026.
New Protocol Support

There are no new protocols in this release.

Updated Protocol Support

ALC, BACapp, C2P, Catapult DCT2000, COTP, CSN.1, DCERPC, DCERPC MAPI, DCERPC NSPI, DNS, DVB-S2-TABLE, eDonkey, EPL, FC ELS, FMP/NOTIFY, H.265, HiPerConTracer, IEEE 802.11, LLS, MEGACO, MIH, MPEG DSM-CC, MS-WSP, RELOAD, SGP.32, SSH, STANAG 4607, UMTS FP, WOWW, and Z39.50

New and Updated Capture File Support

Android Logcat, BLF, DBS Etherwatch, Netlog, and pcapng

New and Updated File Format Decoding Support

There is no new or updated file format support in this release.

Plugin Development Changes

On UN*X systems (excluding macOS when running from an app bundle, as with the official installer) extcap binaries are now searched for under the libexec directory by default, e.g., /usr/libexec/wireshark/extcap instead of /usr/lib64/wireshark/extcap or similar. This is the customary place for helper binaries, which as opposed to libraries do not need multiarch support. The location can be overridden via the environment variable WIRESHARK_EXTCAP_DIR. The extcap binaries shipped with Wireshark are installed in the new location, but third party extcaps may need packaging changes. This change was effective in version 4.6.0, but was not explicitly noted in the release notes previously. Note that some distributions do not use a libexec directory, such as Alpine Linux, which does not have multilib support. On such systems extcap binaries should be in the same location as before.

Prior Versions
Wireshark 4.6.6 included the following changes.

See the release notes for details:

  • wnpa-sec-2026-51 ROHC protocol dissector crash. Issue 21243.
  • Wireshark crashes when run under Visual Studio on Windows. Work item 24787.
  • Welcome page slide preferences are now available in the preferences window.
  • vwr: Read of uninitialized memory in pntoh16. Issue 16460.
  • vwr: Read of uninitialized memory in find_signature. Issue 16461.
  • Upgrades on Windows do not retain existing optional features unless explicitly requested, resulting in accidental removal of features. Issue 18925.
  • Wireshark.exe version 4.6.5 is twice as large as version 4.6.4. Issue 21233.
  • MACsec dissector global-buffer-overflow. Issue 21235.
  • Wireshark 4.6.5 does not run on Windows 10 version 1809 (including Server 2019 and some LTSC versions) Issue 21237.
  • Fuzz job issue: fuzz-2026-05-02-14184750352.pcap. Issue 21240.
  • packet-bacapp: rename aurth-request to auth-request. Issue 21246.
  • Fuzz job issue: randpkt-2026-05-10-14293434231.pcap. Issue 21253.
Wireshark 4.6.5 included the following changes.

See the release notes for details:

  • wnpa-sec-2026-08 Monero dissector crash. Issue 21066. CVE-2026-5409.
  • wnpa-sec-2026-09 BT-DHT dissector crash. Issue 21067. CVE-2026-5408.
  • wnpa-sec-2026-10 FC-SWILS dissector crash. Issue 21070. CVE-2026-5406.
  • wnpa-sec-2026-11 SMB2 dissector infinite loop. Issue 21073. CVE-2026-5407.
  • wnpa-sec-2026-12 ICMPv6 dissector crash. Issue 21077. CVE-2026-5299.
  • wnpa-sec-2026-13 AFP dissector crash. Issue 21088. CVE-2026-5401.
  • wnpa-sec-2026-14 TLS dissector crash and possible code execution. Issue 21090. CVE-2026-5402.
  • wnpa-sec-2026-15 K12 RF5 file parser crash. Issue 21094. CVE-2026-5404.
  • wnpa-sec-2026-16 SBC codec crash and possible code execution. Issue 21103. CVE-2026-5403.
  • wnpa-sec-2026-17 RDP dissector crash and possible code execution. Issue 21105. CVE-2026-5405.
  • wnpa-sec-2026-18 AMR-NB codec crash. Issue 21111. CVE-2026-5654.
  • wnpa-sec-2026-19 SDP dissector crash. Issue 2111. CVE-2026-5655.
  • wnpa-sec-2026-20 iLBC audio codec crash. Issue 21113. CVE-2026-5657.
  • wnpa-sec-2026-21 Profile import crash and possible code execution. Issue 21115. CVE-2026-5656.
  • wnpa-sec-2026-22 DCP-ETSI protocol dissector crash. Issue 21122. CVE-2026-5653.
  • wnpa-sec-2026-23 BEEP protocol dissector crash. Issue 21120. CVE-2026-6538.
  • wnpa-sec-2026-24 ZigBee protocol dissector crash. Issue 21125. CVE-2026-6537.
  • wnpa-sec-2026-25 DLMS/COSEM protcol dissector infinite loop. Issue 21065. CVE-2026-6536.
  • wnpa-sec-2026-26 Dissection engine zlib decompression crash. Issue 21097, Issue 21098. CVE-2026-6535.
  • wnpa-sec-2026-27 USB HID protocol dissector infinite loop. Issue 21121. CVE-2026-6534.
  • wnpa-sec-2026-28 Dissection engine LZ77 decompression crash. Issue 21127. CVE-2026-6533.
  • wnpa-sec-2026-29 Kismet protocol dissector crash. Issue 21129, Issue 21128. CVE-2026-6532.
  • wnpa-sec-2026-30 SANE protocol dissector infinite loop. Issue 21139. CVE-2026-6531.
  • wnpa-sec-2026-31 DCP-ETSI protocol dissector crash. Issue 21144. CVE-2026-6530.
  • wnpa-sec-2026-32 iLBC audio codec crash. Issue 21145. CVE-2026-6529.
  • wnpa-sec-2026-33 TLS dissector infinite loop. Issue 21151. CVE-2026-6528.
  • wnpa-sec-2026-34 ASN.1 PER protocol dissector crash. Issue 21149. CVE-2026-6527.
  • wnpa-sec-2026-35 RTSP protocol dissector crash. Issue 21173. CVE-2026-6526.
  • wnpa-sec-2026-36 IEEE 802.11 protocol dissector crash. Issue 21008. CVE-2026-6525.
  • wnpa-sec-2026-37 MySQL protocol dissector crash. Issue 21172. CVE-2026-6524.
  • wnpa-sec-2026-38 GNW protocol dissector infinite loop. Issue 21177. CVE-2026-6523.
  • wnpa-sec-2026-39 OpenFlow v5 protocol dissector infinite loops. Issue 21182, Issue 21188. CVE-2026-6521.
  • wnpa-sec-2026-40 OpenFlow v6 protocol dissector infinite loop. Issue 21181. CVE-2026-6520.
  • wnpa-sec-2026-41 MBIM dissector infinite loop. Issue 21184. CVE-2026-6519.
  • wnpa-sec-2026-42 RPKI-Router protocol dissector infinite loop. Issue 21186. CVE-2026-6522.
  • wnpa-sec-2026-43 GSM RP protocol dissector crash. Issue 21189. CVE-2026-6870.
  • wnpa-sec-2026-44 WebSocket protocol dissector crash. Issue 21190. CVE-2026-6869.
  • wnpa-sec-2026-45 SMB2 protocol dissector crash. Issue 21191.
  • wnpa-sec-2026-46 HTTP protocol dissector crash. Issue 21185. CVE-2026-6868.
  • wnpa-sec-2026-47 Sharkd utility memory leak. Issue 21214.
  • wnpa-sec-2026-48 Sharkd utility crash. Issue 21206.
  • wnpa-sec-2026-49 Sharkd utility crash. Issue 21207.
  • wnpa-sec-2026-50 UDS protocol dissector infinite loop. Issue 21225.
  • WSUG: Enabled Protocols dialog needs an update. Issue 20871.
  • Build failure with Qt 6.11 beta. Issue 20965.
  • BLF: Missing 4 byte alignment makes BLF files incompatible with Vector’s tools. Issue 21017.
  • SMB2 decryption keys in smb2_seskey_list are not loaded on restart. Issue 21036.
  • Fuzz job issue: fuzz-2026-03-01-13307044520.pcap. Issue 21049.
  • Window with a message for ssh_strict_fopen. Issue 21051.
  • IEEE 1722.1 Dissector for Stream Input Counters displays FRAMES_RX as "Stream Packets TX" Issue 21055.
  • Wireshark 4.6.4 crashes. Issue 21058.
  • Compilation error with Lua-5.5. Issue 21060.
  • BSOD issue affecting Npcap 1.86. Issue 21062.
  • Adding descriptions to BLF interfaces broke the Capture File Properties view. Issue 21069.
  • Assertion Failure in ws_buffer_remove_start via Malformed Packet Manipulation. Issue 21078.
  • Modbus/RTU fails to decode broadcast frames. Issue 21091.
  • Lua not included unless CMake version >= 3.25. Issue 21093.
  • sshdump: Regression in v4.6.4 – Failed to resolve hostname aliases from .ssh/config on Windows. Issue 21114.
  • Fuzz job crash: fuzz-2026-03-25-13637733472.pcap. Issue 21117.
  • dumpcap TCP@ section-header parsing remote heap corruption. Issue 21132.
  • Netflix BBLog EVENT parsing crash. Issue 21133.
  • On Windows, the Follow Stream feature output is shown in proportional font after zooming. Issue 21137.
  • RTP Streams dialog Time of Day inconsistent behavior. Issue 21138.
  • Sysdig Event Block Integer Underflow. Issue 21140.
  • RF4CE NWK Dissector Heap Buffer Overflow (crash/OOB) Issue 21150.
  • NetXray/Sniffer Padding Integer Underflow. Issue 21152.
  • HTTP/2 ALTSVC/PRIORITY_UPDATE Frame Length Truncation (24-bit to 16-bit) Issue 21155.
  • Snort config parser 2 buffer overflows. Issue 21165.
  • ESP NULL Encryption Integer Underflow triggers Heap Overflow. Issue 21166.
  • Heap buffer overflow in ISO 8583 dissector bin2hex() Issue 21171.
  • wslua: NULL pointer dereference in get_dissector when passing an invalid GUID string to an FT_GUID table. Issue 21194.
  • Fuzz job UTF-8 encoding issue: fuzz-2026-04-16-13947406035.pcap. Issue 21199.
  • Qt: Waterfall bars misisng in conversation overview when "limit to display filter" is active. Issue 21204.
  • text2pcap: heap-buffer-overflow in memmove when -P"dissector" payload exceeds reserved space. Issue 21208.
  • text2pcap : Stack overflow via unbounded "g_alloca" in regex "seqno" Issue 21209.
  • editcap: --novlan integer underflow in sll_remove_vlan_info causes denial of service on short SLL captures. Issue 21210.
  • NAS-5GS - Mapping issue between IEI 0x7B and "S-NSSAI location validity information" IE. Issue 21218.
  • RTP-MIDI dissector reports incorrect value for MTC Quarter Frame data. Issue 21231.
Wireshark 4.6.4 included the following changes.

View originalPermalink
How v4.6.7 went
v4.7.2Pre-release

v4.7.2rc0

Tag: v4.7.2rc0

View originalPermalink
How v4.7.2 went
v4.7.1Pre-release

v4.7.1rc0

Tag: v4.7.1rc0

View originalPermalink
How v4.7.1 went
View all

Discussion