Wireshark 4.6.9 Update Patches 19 Vulnerabilities, Fixes RCE via Malicious Packet
Key Takeaways Wireshark has issued critical updates, versions 4.6.9 and 4.4.19, to address 19 documented vulnerabilities. The most severe flaw, CVE-2026-96419, could lead to remote code execution...
Key Takeaways
- Wireshark has issued critical updates, versions 4.6.9 and 4.4.19, to address 19 documented vulnerabilities.
- The most severe flaw, CVE-2026-96419, could lead to remote code execution (RCE) via a malicious configuration profile.
- Multiple other vulnerabilities involve denial-of-service, memory leaks, and infinite loops in various protocol dissectors and capture-file parsers.
- All users are strongly advised to update their Wireshark installations immediately to mitigate these risks.
Wireshark, the ubiquitous network protocol analyzer, has released an urgent security update, version 4.6.9, to remediate 19 identified vulnerabilities. This comprehensive patch addresses issues spanning protocol dissectors, capture-file parsers, the Sharkd utility, and configuration profile management. The update, released on September 23, is available for Windows and macOS, alongside a parallel update, Wireshark 4.4.19, for the older maintenance branch.
Table Of Content
Given Wireshark’s critical role in network troubleshooting, security analysis, and software development, particularly its frequent use with data from untrusted sources, flaws in its core parsing and dissection components represent a significant security risk to analyst workstations. Such vulnerabilities can extend beyond mere operational disruption to direct system compromise.
Critical Vulnerabilities Addressed in Wireshark 4.6.9
Remote Code Execution via Malicious Profile
The most pressing vulnerability is CVE-2026-96419 (tracked as wnpa-sec-2026-106). This flaw allows a specially crafted configuration profile to trigger a crash or potentially enable arbitrary code execution on a user’s system if they are enticed into importing it. The vulnerability impacts Wireshark versions 4.6.0 through 4.6.8 and the 4.4 branch from 4.4.0 through 4.4.18. The fixes are incorporated into versions 4.6.9 and 4.4.19.
While Wireshark’s advisory indicates no known active exploitation, the required user interaction does not diminish the threat. A malicious profile could be distributed through common attack vectors such as phishing campaigns, shared analysis packages, support interactions, or untrusted repositories, deceptively presented as a legitimate troubleshooting configuration.
Denial of Service and Resource Exhaustion Flaws
The remaining advisories detail a range of issues, including crashes, excessive loops, memory leaks, and denial-of-service (DoS) conditions, all triggered by the processing of malformed data. Affected components include numerous protocol dissectors such as ZigBee ZCL, SCTP, SPDY, CSN.1, MBIM, Frame, RF4CE, TIFF, X11, IEEE 802.11, Catapult DCT2000, USB HID, and IEEE C37.118 Synchrophasor. Additionally, parsers for TTL, PEAK CAN TRC, Microsoft Network Monitor, and Toshiba capture files are impacted, along with a flaw that can crash Sharkd.
Several defects contribute to resource exhaustion without immediate application termination. Specifically, the TTL and TIFF issues can induce infinite loops, Microsoft Network Monitor parsing might enter extensive loops, the Synchrophasor dissector exhibits memory leaks, and USB HID processing combines an infinite loop with a memory leak. Such vulnerabilities could lead to hung analysis sessions, depletion of system resources, or disruption of automated processing pipelines.
Additional Security-Relevant Bug Fixes
Beyond the 19 CVE-backed advisories, Wireshark 4.6.9 incorporates fixes for several other security-relevant bugs. These include a DICOM heap overwrite resulting from a 32-bit length wrap, integer overflows in LBMC fragment reassembly and Bluetooth AVCTP, an SMB object-export integer overflow, a PKCS12 null-pointer dereference, and a stack-based buffer overflow in etwdump when parsing crafted ETL files.
The release notes also highlight corrections for two separately tracked remote-code-execution flaws related to LBMC fragment reassembly and LoRaWAN decryption. Further fixes address out-of-bounds reads, an uninitialized buffer pointer, excessive DICOM memory amplification, and incorrect handling of GREASE values during JA4 fingerprint calculation. These corrections are crucial for Security Operations Center (SOC) teams, as parser reliability and fingerprint accuracy directly influence triage, detection engineering, and forensic analysis.
While no new protocols were introduced, the update enhances support for technologies such as QUIC, SMB, OpenFlow, DICOM, LoRaWAN, IEEE 802.11, X11, ZigBee ZCL, and SPDY. Capture-file updates cover BLF, Network Monitor, pcapng, PEAK TRC, Toshiba, and TTL formats.
What You Should Do
- Immediate Update: All organizations and individual users should promptly upgrade to Wireshark 4.6.9. If operating on the older maintenance branch, update to 4.4.19 or a later version. Official packages are available from Wireshark’s download page.
- Exercise Caution: Until updates are fully deployed, avoid importing configuration profiles or opening capture files from unverified or untrusted sources.
- Isolate Risky Analysis: Conduct any analysis of potentially malicious or untrusted capture files within a sandboxed environment or a disposable virtual machine.
- Restrict Privileges: Limit the privileges of automated processing pipelines that handle network captures, especially those originating from external or untrusted sources.
- Endpoint Audit: Administrators should audit analyst endpoints, jump boxes, forensic workstations, and centrally managed capture appliances to ensure all Wireshark installations are updated.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.