Wireshark 4.6.9 Fixes 19 Vulnerabilities in Dissectors and File Parsers

Wireshark 4.6.9 Fixes 19 Vulnerabilities in Dissectors and File Parsers

Wireshark 4.6.9 was released on September 23. It is a maintenance release, but a maintenance release with 19 vulnerability fixes, which makes it a real update rather than an optional one.

Why a packet analyzer has so many security bugs

Wireshark’s job is to parse untrusted binary data in thousands of formats. Every protocol dissector is a parser written against a spec, fed whatever arrives on the wire or in a capture file someone sent you. A malformed packet that crashes a dissector, or worse, is a standing risk.

The 19 fixes span dissectors and file parsers including ZigBee ZCL, SPDY, CSN.1, USB HID, TIFF, X11, RF4CE, MBIM, and IEEE 802.11. Most were found through fuzzing.

The practical advice has not changed in years: do not capture as root with the GUI. Capture with dumpcap or tcpdump as a privileged user, and analyze the file as a normal one, so a dissector bug cannot run with root privileges.

# capture privileged, analyze unprivileged
sudo tcpdump -i any -w /tmp/cap.pcap
wireshark /tmp/cap.pcap

On most distros, adding yourself to the wireshark group lets dumpcap capture without running the GUI as root at all.

Protocol and file format updates

More than 30 dissectors got updates, including AKP, Bencode, Bluetooth AVCTP, BSSLAP, DICOM, F1AP, OpenFlow, QUIC, and ZigBee ZCL. Capture file support improved for BLF, Network Monitor, pcapng, PEAK TRC, Toshiba, and TTL formats.

Other fixes include SMB object export, Bluetooth AVCTP multipart reassembly, PKCS#12 PBE decryption, LoRaWAN decryption, a UTF-8 encoding bug, and where extcap binaries are looked up on Unix systems.

Getting it

It is available from distribution repositories as they update, and on Flathub. If you mostly work on servers, our tcpdump guide covers capturing there and opening the file in Wireshark later, and the tcpdump filter builder helps write capture filters.

Background reading

Explainers for the concepts behind this story.