Wireshark 4.6.3 Released With Vulnerabilities Dissector and Parser Crash
The Wireshark Foundation has announced the release of Wireshark 4.6.3, an update to the widely used network protocol analyzer.
The Wireshark Foundation has announced the release of Wireshark 4.6.3, an update to the widely used network protocol analyzer.
This update is crucial for network administrators, security analysts, and developers due to the resolution of multiple security vulnerabilities that could potentially lead to denial-of-service (DoS) conditions through dissector and parser crashes.
The update addresses four specific vulnerabilities in the dissector and parser modules that could be exploited to disrupt Wireshark operations. These vulnerabilities allowed attackers to inject malformed data into a network stream or capture file.
Details of the resolved security issues in version 4.6.3 are as follows:
Vulnerability ID Component Issue Type Reference
wnpa-sec-2026-01 BLF File Parser Application Crash Issue 20880
The Wireshark Foundation has announced the release of Wireshark 4.6.3, an update to the widely used network protocol analyzer.
wnpa-sec-2026-02 IEEE 802.11 Dissector Dissector Crash Issue 20939
wnpa-sec-2026-03 SOME/IP-SD Dissector Dissector Crash Issue 20945
wnpa-sec-2026-04 HTTP3 Dissector Infinite Loop Issue 20944
The HTTP3 dissector infinite loop ( wnpa-sec-2026-04 ) is notably significant as it can lead to high CPU utilization, making the analysis machine unresponsive. Crashes in the IEEE 802.11 and SOME/IP-SD modules also underscore the risks in wireless and automotive protocol analysis.
In addition to security patches, Wireshark 4.6.3 introduces several functional improvements and bug fixes:
Solaris Build Fix : Resolved a compilation error in Wireshark 4.6.0 related to pcapio.c , restoring Solaris system compatibility. RTP Player : Fixed a bug preventing RTP player streams from stopping, enhancing VoIP traffic analysis. Data Parsing Errors : Corrected issues with missing data in HomePlug messages and improper parsing of IEEE 802.11 QoS fields when A-MSDU is present. MaxMind DB : Patched a crash occurring when switching profiles with MaxMind DB enabled or disabled.
Furthermore, protocol support has been updated for DHCP, SSH, HTTP3, QUIC, LTE RRC, NAS-5GS, H.248, HomePlug AV, SOME/IP-SD, and IEEE 802.11. Capture file support has improved for 3GPP TS 32.423 Trace, BLF, NetScreen, and Viavi Observer formats.
Wireshark is maintained by the Wireshark Foundation, which focuses on protocol analysis education. Community contributions sustain the project's development.
Professionals are advised to upgrade to Wireshark 4.6.3 to mitigate the risks associated with the patched vulnerabilities. The installer and source code are available on the official Wireshark download page.
Based on reporting by Cyber Security News.
