Wireshark 4.6.6 Patches Dissector Crash Vulnerability
Key Takeaways Wireshark 4.6.6 has been released, primarily to patch a critical vulnerability in its ROHC protocol dissector. The flaw, identified as wnpa-sec-2026-51, could enable an attacker to...
Key Takeaways
- Wireshark 4.6.6 has been released, primarily to patch a critical vulnerability in its ROHC protocol dissector.
- The flaw, identified as wnpa-sec-2026-51, could enable an attacker to crash the Wireshark application using a specially crafted packet.
- This update also addresses a MACsec dissector buffer overflow and over a dozen other stability and compatibility issues, particularly affecting Windows users.
- All users, especially those in production or monitoring environments, are strongly advised to update immediately.
Critical Wireshark Update Patches Dissector Crash Vulnerability
The Wireshark Foundation has rolled out Wireshark 4.6.6, an urgent update primarily focused on mitigating a significant security vulnerability within the Robust Header Compression (ROHC) protocol dissector. This flaw presents a denial-of-service risk, allowing an attacker to trigger an application crash through the injection of a meticulously designed, malformed packet. In addition to this critical patch, the release also resolves more than a dozen other bugs impacting the stability and compatibility of the popular network analyzer, particularly for Windows users.
Table Of Content
ROHC Dissector Vulnerability Explained
The primary security concern addressed in this release is designated wnpa-sec-2026-51, a confirmed dissector crash vulnerability tracked internally as Issue 21243. This vulnerability resided within Wireshark’s ROHC protocol dissector, a critical component responsible for accurately parsing and interpreting compressed IP packet headers. Exploitation of this flaw could occur if a threat actor were to introduce a malformed packet into a live network capture or supply a manipulated .pcap file. Such an action would provoke an unhandled crash within Wireshark, potentially disrupting ongoing network analysis workflows and destabilizing critical monitoring infrastructure.
Furthermore, the update rectifies a global-buffer-overflow vulnerability in the MACsec dissector, identified as Issue 21235. This flaw posed a memory safety risk when Wireshark processed traffic secured by IEEE 802.1AE. Both the ROHC and MACsec vulnerabilities were brought to light through extensive fuzz testing campaigns conducted in May 2026, highlighting the effectiveness of proactive security assessments.
Bug Fixes and Stability Improvements
Beyond the critical security patches, Wireshark 4.6.6 introduces a suite of important bug fixes and stability enhancements:
- Windows Crash under Visual Studio (Work Item 24787): A regression affecting the development environment on Windows has been resolved.
- Uninitialized Memory Reads: Specific issues involving uninitialized memory reads were fixed in the
pntoh16andfind_signaturefunctions within the VeriWave (vwr) file reader (Issues 16460, 16461). - Windows 10 v1809 Incompatibility: Previous versions of Wireshark (4.6.5) experienced failures to launch on Windows 10 version 1809, Server 2019, and certain LTSC editions (Issue 21237), which has now been rectified.
- Accidental Feature Removal on Windows: A problem where optional features were inadvertently removed during upgrades on Windows systems, if not explicitly preserved, has been addressed (Issue 18925).
- Executable Size Bloat: The
Wireshark.exefor version 4.6.5 was noted to be double the size of 4.6.4 due to a packaging issue (Issue 21233), which this release corrects. - Two additional fuzz job crashes stemming from May 2026 capture files (Issues 21240, 21253) have also been resolved.
This release integrates Npcap 1.88, an upgrade from the previously bundled Npcap 1.87, which is expected to enhance low-level packet capture reliability on Windows platforms. While no entirely new protocols were introduced, the update includes improved dissector support for various existing protocols, including BACapp, MACsec, ROHC, Kafka, SIP, PFCP, and BPv7. Furthermore, support for capture file formats such as JSON and VeriWave has been updated.
For Unix-based systems, extcap binaries will now default to the /usr/libexec/wireshark/extcap directory. This change, initially implemented in version 4.6.0, is now formally documented with this release.
What You Should Do
- Update Immediately: All users, particularly security teams and network analysts operating Wireshark in production or monitoring environments, should update to version 4.6.6 without delay.
- Prioritize Untrusted Environments: Given the ROHC dissector crash risk, prioritize updating systems that process untrusted or external packet captures.
- Download from Official Sources: Always download the latest version directly from the official Wireshark website to ensure authenticity and integrity. Downloads are available at wireshark.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.