Wireshark 4.6.8 Security Update: 28 Critical Fixes, 9 in File Parsers

www.news4hackers.com-wireshark-4-6-8-security-update-28-critical-fixes-9-in-file-parsers-wireshark-4-6-8-security-update-28-critical-fixes-9-in-file-parsers

Wireshark 4.6.8 addresses 28 security vulnerabilities, including nine impacting file format handlers and critical protocol dissectors.

Security Vulnerabilities in Wireshark 4.6.8

Vulnerabilities in File Format Handlers

Wireshark 4.6.8 addresses 28 security vulnerabilities, with nine impacting file format handlers that process saved capture files. These nine flaws reside in the code responsible for reading data from disk prior to protocol analysis, specifically affecting pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Catapult DCT2000, Gammu DCT3, 3gpp phone logs, TTX Logger, and Windows-specific formats Ixia IxVeriWave and Vector Informatik BLF. Attackers can exploit these vulnerabilities by distributing malicious capture files, requiring no network interaction.

Fixes and Advisories

The fixes span advisories wnpa-sec-2026-64 through wnpa-sec-2026-91, with most addressing protocol dissectors—components that translate raw packet data into structured fields. Crashes were resolved in RDP, SSH, Kerberos, H.245, ESS, X.509IF, RRC, and UMTS FP protocols, alongside multiple advisories for CMS, C12.22, and Bluetooth-related protocols. A reassembly engine fix also impacts all dissectors by addressing fragmented data reconstruction.

Reassembly Engine and Command-Line Tool

Two vulnerabilities affect the command-line tool sharkd, exposing scripted workflows to similar risks. Testing efforts, including fuzzing, contributed to the majority of these patches. The preceding version, 4.6.7, included 12 advisories.

Memory-Safety Issues

Memory-safety issues without formal advisory designations include a stack buffer overflow in the K12/RF5 writer, a stack over-read in the Sniffer REC_HEADER2 error path, an out-of-bounds read in androiddump due to a signed btsnoop length, an out-of-bounds read in the BLF writer when processing truncated VLAN-tagged frames, and stack exhaustion from deeply nested NetLog JSON or recursive DLMS/COSEM compact-array parsing. These flaws highlight the complexity of handling malformed input across diverse protocols.

Incorrect Decoding in 5G Network Elements

A separate set of issues involves incorrect decoding of eight 5G network elements. Wireshark misinterpreted S-NSSAI location validity, NSAG information, UE security capability, Registration wait range, Extended CAG information, SOR transparent container, SOR-CMCI field, and service level AA container in 5G NAS and 5GSM protocols. While no crashes occurred, these errors could lead to misinformed network analysis, as the incorrect values appeared valid to users.

Extcap Binary Path Update

The release also updates the extcap binary path for UN*X systems, relocating it to /usr/libexec/wireshark/extcap from previous locations like /usr/lib64/wireshark/extcap. This change, effective since version 4.6.0, requires adjustments for third-party extcap tools, though Alpine Linux retains the older path.

Windows Usability Improvements

Windows users benefit from two usability improvements: resolving a performance issue in Capture File Properties that caused application freezes and fixing a segmentation fault triggered by toggling TCP sequence number analysis.

Conclusion

The update underscores the ongoing challenge of securing protocol analysis tools against increasingly sophisticated attack vectors, emphasizing the importance of rigorous testing and community-driven vulnerability disclosure.



About Author

en_USEnglish