Wireshark 4.6.6
Wireshark is the standard open-source network protocol analyzer, capturing and inspecting traffic in detail for troubleshooting, security analysis, and protocol development.
Download TAR.XZ Project website ↗Download Mirrors
Wireshark is the de facto standard for packet capture and protocol analysis, used by network administrators, security analysts, and developers debugging protocol implementations. It decodes hundreds of protocols in detail, from basic TCP/IP to application-layer protocols like HTTP, DNS, and TLS handshakes.
Security Fixes in 4.6.6
This release addresses two notable issues: a crash in the ROHC (Robust Header Compression) dissector triggered by malformed capture data, and a buffer overflow in the MACsec dissector. Both are the kind of vulnerability class relevant to anyone opening capture files from untrusted sources, which is a common workflow when sharing .pcap files for troubleshooting help.
What Else Changed
Third-party extcap plugin discovery has been restructured, now defaulting to /usr/libexec/wireshark/extcap with environment variable overrides available for custom setups. Protocol decoders for Kafka, SIP, and several industrial protocols were also updated, alongside native JSON capture file support.
Installing on Linux
Most distributions package Wireshark directly:
# Debian/Ubuntu
sudo apt install wireshark
# Fedora
sudo dnf install wireshark
Non-root packet capture requires adding your user to the wireshark group (Debian/Ubuntu) or configuring capabilities on dumpcap directly, rather than running the whole GUI as root.
Verify Your Download
SHA256 checksums and PGP signatures are published at wireshark.org/download.html.