< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Wireshark releases 4.6.8 with 31 security patches

The Wireshark Foundation has released version 4.6.8 of its open-source network protocol analyzer, featuring 31 security patches. This represents the largest single-release hardening effort in the tool's history. The updates primarily address vulnerabilities that cause crashes or abnormal exits when processing malformed capture files or specific protocol dissectors.

Key areas of improvement include fixes for the Bluetooth stack, 5G telecom protocols, and the network-facing sharkd daemon. The release also addresses memory corruption risks and out-of-bounds read vulnerabilities across various dissectors, including SSH, Kerberos, RDP, and CMS. Additionally, the update resolves issues within parsers for formats such as pcapng, ERF dumps, and 3GPP phone logs.

For long-term support users, the Wireshark Foundation has also released version 4.4.18. Administrators using Unix-like systems should note a packaging change where extcap binaries now default to /usr/libexec/wireshark/extcap.

Entities

Wireshark · Wireshark Foundation