# Wireshark v4.4.17 - Product: Wireshark (https://whatsnew.fyi/product/wireshark) - Vendor: Wireshark Foundation - Date: 2026-07-08 - Version: v4.4.17 - Original notes: https://gitlab.com/wireshark/wireshark/-/tags/v4.4.17 - Permalink: https://whatsnew.fyi/product/wireshark/releases/v4.4.17 - Labels: Platforms: Desktop What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- Tag: v4.4.17 - **security** — Fixed Catapult DCT2000 protocol dissector crash - **security** — Fixed FMP/NOTIFY protocol dissector large loop - **security** — Fixed SSH protocol dissector crash - **security** — Fixed IEEE 802.11 protocol dissector crash - **security** — Fixed Z39.50 protocol dissector crash - **security** — Fixed UMTS FP protocol dissector crash - **security** — Fixed BLF file parser information disclosure - **security** — Fixed multiple protocol dissector infinite loops - **security** — Fixed DBS Etherwatch file parser crash - **security** — Fixed Ciscodump extcap crash - **fixed** — Fixed build failure with Qt 6.11 beta - **fixed** — Fixed BACapp error parsing you-are request - **fixed** — Fixed UTF-8 encoding issue in fuzzing - **fixed** — Fixed memory leak in packet capture file - **fixed** — Fixed heap-buffer-overflow in Wireshark Logcat Parser - **fixed** — Fixed HEVC (H.265) dissector bit_offset advancement after sub_layer_hrd_parameters() causing false Malformed Packet - **fixed** — Fixed heap-buffer-overflow in dfilter_compile_full with time literal - **fixed** — Fixed Wireshark crash with HEAP_CORRUPTION error when using last saved recent_common file - **changed** — Windows installers now ship with Qt 6.7.3 instead of Qt 6.5.3 - **changed** — Windows installers are now built with Visual Studio 2026 #### Wireshark 4.4.17 Release Notes ##### What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. Wireshark is hosted by the Wireshark Foundation, a nonprofit which promotes protocol analysis education. Wireshark and the foundation depend on your contributions in order to do their work! If you or your organization would like to contribute or become a sponsor, please visit wiresharkfoundation.org. ##### What’s New ###### Bug Fixes The following vulnerabilities have been fixed: - wnpa-sec-2026-52 Catapult DCT2000 protocol dissector crash. Issue 21270. - wnpa-sec-2026-54 FMP/NOTIFY protocol dissector large loop. Issue 21347. - wnpa-sec-2026-55 SSH protocol dissector crash. Issue 21378. - wnpa-sec-2026-57 IEEE 802.11 protocol dissector crash. Issue 21391. - wnpa-sec-2026-58 Z39.50 protocol dissector crash. Issue 21397. - wnpa-sec-2026-59 UMTS FP protocol dissector crash. Issue 21398. - wnpa-sec-2026-60 BLF file parser information disclosure. Issue 21361. - wnpa-sec-2026-61 Multiple protocol dissector infinite loops. Issue 21275, Issue 21277, Issue 21330, Issue 21383. - wnpa-sec-2026-62 DBS Etherwatch file parser crash. Issue 21352. - wnpa-sec-2026-63 Ciscodump extcap crash. Issue 21375. The following bugs have been fixed: - Build failure with Qt 6.11 beta. Issue 20965. - BACapp: Error parsing you-are request. Issue 21260. - Fuzz job issue: fuzz-2026-05-24-14517548985.pcap. Issue 21272. - Fuzz job UTF-8 encoding issue: fuzz-2026-06-07-14732586286.pcap. Issue 21331. - Memory leak in alp-sample1.pcap. Issue 21343. - Heap-Buffer-Overflow in Wireshark Logcat Parser. Issue 21346. - HEVC (H.265) dissector: bit_offset not advanced after sub_layer_hrd_parameters() causes false Malformed Packet. Issue 21362. - dfilter_compile_full: heap-buffer-overflow READ in ws_strptime on a time literal. Issue 21376. - Wireshark crashes with a HEAP_CORRUPTION error when using the last saved recent_common file. Issue 21379. - Fuzz job issue: fuzz-2026-06-30-15106674620.pcap. Issue 21381. ###### New and Updated Features - The Windows installers now ship with Qt 6.7.3. They previously shipped with Qt 6.5.3. - The Windows installers are now built with Visual Studio 2026. ###### New Protocol Support There are no new protocols in this release. ###### Updated Protocol Support ALC, BACapp, Catapult DCT2000, COTP, CSN.1, DNS, eDonkey, FC ELS, FMP/NOTIFY, H.265, IEEE 802.11, LLS, MEGACO, MIH, MPEG DSM-CC, RELOAD, SSH, UMTS FP, WOWW, and Z39.50 ###### New and Updated Capture File Support Android Logcat, BLF, and DBS Etherwatch ###### New and Updated File Format Decoding Support There is no updated file format support in this release. ##### Prior Versions Wireshark 4.4.16 included the following changes. See the release notes for details: - vwr: Read of uninitialized memory in pntoh16. Issue 16460. - vwr: Read of uninitialized memory in find_signature. Issue 16461. - Fuzz job issue: fuzz-2026-05-02-14184750352.pcap. Issue 21240. - ROHC NULL Write / Heap Corruption with uncompressed profile and large CID. Issue 21243. - Fuzz job crash: fuzz-2026-05-18-14414274873.pcap. Issue 21261. Wireshark 4.4.15 included the following changes. See the release notes for details: - wnpa-sec-2026-08 Monero dissector crash. Issue 21066. CVE-2026-5409. - wnpa-sec-2026-09 BT-DHT dissector crash. Issue 21067. CVE-2026-5408. - wnpa-sec-2026-10 FC-SWILS dissector crash. Issue 21070. CVE-2026-5406. - wnpa-sec-2026-11 SMB2 dissector infinite loop. Issue 21073. CVE-2026-5407. - wnpa-sec-2026-12 ICMPv6 dissector crash. Issue 21077. CVE-2026-5299. - wnpa-sec-2026-13 AFP dissector crash. Issue 21088. CVE-2026-5401. - wnpa-sec-2026-15 K12 RF5 file parser crash. Issue 21094. CVE-2026-5404. - wnpa-sec-2026-16 SBC codec crash and possible code execution. Issue 21103. CVE-2026-5403. - wnpa-sec-2026-17 RDP dissector crash and possible code execution. Issue 21105. CVE-2026-5405. - wnpa-sec-2026-18 AMR-NB cod _[Truncated at 4000 characters — full notes: https://gitlab.com/wireshark/wireshark/-/tags/v4.4.17]_