Wireshark has shipped a security-focused update that closes 19 documented vulnerabilities across the network analyzer’s protocol dissectors, capture-file readers, Sharkd utility and profile handling. The breadth of the fixes matters because packet analyzers regularly process material collected from systems that may already be compromised. A capture file or troubleshooting profile is evidence, but it is also attacker-controlled input.
Versions 4.6.9 and 4.4.19 were released for users on the current and older maintenance branches. Organizations that rely on Wireshark for incident response, troubleshooting or classroom use should move to one of those fixed versions, with priority given to security operations centers, forensic workstations and shared analysis servers.
Configuration profile creates the clearest code-execution concern
The most consequential issue is CVE-2026-96419. A maliciously prepared configuration profile can crash the application and may allow arbitrary code execution if a user imports it. Affected releases include Wireshark 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.
Importing a profile requires user action, but that does not make the scenario remote from normal operations. Profiles may be exchanged in support tickets, team repositories and incident-response packages. An attacker could describe one as a required decoding setup or a configuration that reveals hidden traffic, giving the file a credible social-engineering wrapper.
Wireshark’s advisory says there is no known active exploitation. Even so, the potential impact makes prompt installation prudent, especially on machines that hold privileged credentials or can reach sensitive management networks.
Malformed traffic can crash or exhaust analysis systems
The remaining advisories cover crashes, resource consumption, memory leaks and loops in a wide variety of dissectors and parsers. Affected areas include ZigBee ZCL, SCTP, SPDY, MBIM, RF4CE, TIFF, X11, IEEE 802.11, USB HID and the IEEE C37.118 Synchrophasor format. File readers for TTL, PEAK CAN TRC, Microsoft Network Monitor and Toshiba captures are also among the corrected components.
Several bugs can keep a parser busy rather than immediately terminating it. Crafted TTL and TIFF data can trigger infinite loops, Network Monitor input can cause an unusually large loop, and some USB HID or Synchrophasor processing can leak memory. On a desktop, that may look like a frozen application. In an automated pipeline, repeated hostile files could consume capacity or delay time-sensitive investigations.
The release also addresses security-relevant defects outside the 19 CVE-backed advisories. They include integer overflows in LBMC reassembly, Bluetooth AVCTP and SMB object export; a DICOM heap overwrite linked to a length wrap; a PKCS12 null-pointer dereference; and a stack buffer overflow in the etwdump tool when it parses crafted ETL data. Separately tracked code-execution bugs involving LBMC reassembly and LoRaWAN decryption were corrected as well.
Why defensive tools deserve the same input controls
Security software is often trusted more than ordinary productivity applications, yet its job is to parse some of the least trustworthy data in an organization. Analysts may open packets captured near an attacker, files supplied by an external party or artifacts recovered from an infected host. Parser flaws can turn that normal workflow into a route from suspicious evidence to the investigator’s machine.
Organizations should therefore combine patching with containment. Practical steps include:
- Upgrade endpoints to Wireshark 4.6.9 or the supported 4.4.19 maintenance release.
- Reject unsolicited profiles and verify shared analysis packages through a trusted channel.
- Open risky captures in a disposable virtual machine with limited credentials and network access.
- Run automated parsing services with minimal privileges, resource limits and isolation from production systems.
- Inventory centrally managed analyst endpoints, jump hosts and capture appliances rather than relying on voluntary desktop updates.
Reliability fixes also protect investigation quality
The update improves handling for protocols and formats including QUIC, SMB, OpenFlow, DICOM, LoRaWAN, pcapng and Network Monitor. It also corrects out-of-bounds reads, excessive DICOM memory use and errors in GREASE handling during JA4 fingerprint calculation.
Those fixes are not merely about availability. A crash can interrupt evidence review, while incorrect parsing or fingerprinting can distort a detection engineer’s conclusions. Updating reduces both direct exploitation risk and the possibility that an analyst makes a decision from incomplete or incorrectly decoded traffic.
Source: Cyber Security News.
Leave a Reply
You must be logged in to post a comment.