Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Teams to Gain New Security Detection Reporting Feature
August 9, 2026
Critical Metabase Vulnerability Exploited to Gain Admin Access
August 9, 2026
Cisco IOS XE Zero-Day Exploited, OWASP Top 10 for LLM
August 9, 2026
Home/CyberSecurity News/Wireshark 4.6.6 Patches Dissector Crash Vulnerability
CyberSecurity News

Wireshark 4.6.6 Patches Dissector Crash Vulnerability

Key Takeaways Wireshark 4.6.6 has been released, primarily to patch a critical vulnerability in its ROHC protocol dissector. The flaw, identified as wnpa-sec-2026-51, could enable an attacker to...

Sarah simpson
Sarah simpson
May 25, 2026 3 Min Read
58 0

Key Takeaways

  • Wireshark 4.6.6 has been released, primarily to patch a critical vulnerability in its ROHC protocol dissector.
  • The flaw, identified as wnpa-sec-2026-51, could enable an attacker to crash the Wireshark application using a specially crafted packet.
  • This update also addresses a MACsec dissector buffer overflow and over a dozen other stability and compatibility issues, particularly affecting Windows users.
  • All users, especially those in production or monitoring environments, are strongly advised to update immediately.

Critical Wireshark Update Patches Dissector Crash Vulnerability

The Wireshark Foundation has rolled out Wireshark 4.6.6, an urgent update primarily focused on mitigating a significant security vulnerability within the Robust Header Compression (ROHC) protocol dissector. This flaw presents a denial-of-service risk, allowing an attacker to trigger an application crash through the injection of a meticulously designed, malformed packet. In addition to this critical patch, the release also resolves more than a dozen other bugs impacting the stability and compatibility of the popular network analyzer, particularly for Windows users.

Table Of Content

  • Key Takeaways
  • Critical Wireshark Update Patches Dissector Crash Vulnerability
  • ROHC Dissector Vulnerability Explained
  • Bug Fixes and Stability Improvements
  • What You Should Do

ROHC Dissector Vulnerability Explained

The primary security concern addressed in this release is designated wnpa-sec-2026-51, a confirmed dissector crash vulnerability tracked internally as Issue 21243. This vulnerability resided within Wireshark’s ROHC protocol dissector, a critical component responsible for accurately parsing and interpreting compressed IP packet headers. Exploitation of this flaw could occur if a threat actor were to introduce a malformed packet into a live network capture or supply a manipulated .pcap file. Such an action would provoke an unhandled crash within Wireshark, potentially disrupting ongoing network analysis workflows and destabilizing critical monitoring infrastructure.

Furthermore, the update rectifies a global-buffer-overflow vulnerability in the MACsec dissector, identified as Issue 21235. This flaw posed a memory safety risk when Wireshark processed traffic secured by IEEE 802.1AE. Both the ROHC and MACsec vulnerabilities were brought to light through extensive fuzz testing campaigns conducted in May 2026, highlighting the effectiveness of proactive security assessments.

Bug Fixes and Stability Improvements

Beyond the critical security patches, Wireshark 4.6.6 introduces a suite of important bug fixes and stability enhancements:

  • Windows Crash under Visual Studio (Work Item 24787): A regression affecting the development environment on Windows has been resolved.
  • Uninitialized Memory Reads: Specific issues involving uninitialized memory reads were fixed in the pntoh16 and find_signature functions within the VeriWave (vwr) file reader (Issues 16460, 16461).
  • Windows 10 v1809 Incompatibility: Previous versions of Wireshark (4.6.5) experienced failures to launch on Windows 10 version 1809, Server 2019, and certain LTSC editions (Issue 21237), which has now been rectified.
  • Accidental Feature Removal on Windows: A problem where optional features were inadvertently removed during upgrades on Windows systems, if not explicitly preserved, has been addressed (Issue 18925).
  • Executable Size Bloat: The Wireshark.exe for version 4.6.5 was noted to be double the size of 4.6.4 due to a packaging issue (Issue 21233), which this release corrects.
  • Two additional fuzz job crashes stemming from May 2026 capture files (Issues 21240, 21253) have also been resolved.

This release integrates Npcap 1.88, an upgrade from the previously bundled Npcap 1.87, which is expected to enhance low-level packet capture reliability on Windows platforms. While no entirely new protocols were introduced, the update includes improved dissector support for various existing protocols, including BACapp, MACsec, ROHC, Kafka, SIP, PFCP, and BPv7. Furthermore, support for capture file formats such as JSON and VeriWave has been updated.

For Unix-based systems, extcap binaries will now default to the /usr/libexec/wireshark/extcap directory. This change, initially implemented in version 4.6.0, is now formally documented with this release.

What You Should Do

  • Update Immediately: All users, particularly security teams and network analysts operating Wireshark in production or monitoring environments, should update to version 4.6.6 without delay.
  • Prioritize Untrusted Environments: Given the ROHC dissector crash risk, prioritize updating systems that process untrusted or external packet captures.
  • Download from Official Sources: Always download the latest version directly from the official Wireshark website to ensure authenticity and integrity. Downloads are available at wireshark.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Supply Chain Attack Compromises 34 npm, PyPI, and Crates Packages

Next Post

Pentest Agent Suite Bug Exposes Claude Code and 6 AI Coding Tools

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us