← Downloads

Wireshark 4.6.8

Package v4.6.8 x86_64 TAR.XZ August 12, 2026

Wireshark 4.6.8 is a maintenance release of the network protocol analyzer, carrying bug fixes and protocol dissector updates.

Download TAR.XZ Project website ↗

Download Mirrors

Mirror Region Download
Wireshark Downloads (Official) Primary Global Download
Wireshark Source Global Download
Wireshark Release Notes Global Download

Wireshark is the standard tool for capturing and inspecting network traffic, and 4.6.8 is a maintenance release with bug fixes and protocol dissector updates.

Why dissector updates matter

Most of what Wireshark does is understand protocols. It captures raw bytes off the wire and then decodes them into structured, readable fields, which requires a dissector that knows the protocol in question.

Protocols change. New ones appear, existing ones add extensions, and vendors ship variations. A maintenance release that updates dissectors is keeping pace with a moving target, and the practical effect is that traffic which previously showed as opaque payload now decodes properly.

Basic usage

# List available interfaces
sudo wireshark -D

# Capture on an interface with a display filter
sudo wireshark -i eth0 -f "port 443"

# Terminal version, useful over SSH
sudo tshark -i eth0 -f "port 53" -Y "dns.flags.response == 0"

# Read a capture taken elsewhere
wireshark capture.pcapng

The distinction between capture filters and display filters trips up newcomers constantly. Capture filters use BPF syntax and decide what gets recorded; display filters use Wireshark’s own syntax and decide what you see from what was recorded. You cannot recover traffic a capture filter excluded.

Running it without root

Capturing packets needs elevated privileges, and running the full GUI as root is a bad idea given the amount of untrusted input it parses.

The correct approach is to grant capture capabilities to dumpcap and add yourself to the wireshark group:

sudo dpkg-reconfigure wireshark-common   # Debian and Ubuntu
sudo usermod -aG wireshark "$USER"
# Log out and back in

Wireshark’s dissectors have historically been a rich source of security vulnerabilities, precisely because they parse hostile input from the network. Not running the GUI as root is a meaningful precaution rather than a formality.

Where it fits

For quick checks, ss and tcpdump are usually faster. Wireshark earns its place when you need to follow a TCP stream, decode TLS with a key log file, or explain to someone else what a protocol exchange actually did.

Our guide to checking network connections with ss and nmcli covers the lighter tools, and Linux networking basics covers the concepts underneath.

Verify Your Download

Source releases are published with SHA-256 checksums and GPG signatures on the download page.