Wireshark 4.6.7 resolves security flaws and repairs HEVC dissector bug
Wireshark has released version 4.6.7, which patches 12 security vulnerabilities, including several crash-inducing bugs in protocol dissectors. The update also includes a specific repair for an HEVC dissector bit-offset bug that previously caused false malformed packet flags for video engineers.
Key Takeaways
- Patches 12 vulnerabilities, including crash-causing memory errors in SSH, IEEE 802.11, and pcapng file readers.
- Repairs a specific HEVC video dissector bug where an un-advanced bit offset caused packets to be incorrectly flagged as malformed.
- Updates Windows installers to be built with the Visual Studio 2026 toolchain.
- Documents a structural shift for UN*X systems, moving extcap helper binaries to the libexec directory by default.
- Remedies multiple infinite loop flaws in the FMP/NOTIFY dissector and an information disclosure bug in the BLF file parser.
Why It Matters
For streaming engineers, this release provides critical stability for HEVC and H.265 packet analysis, eliminating false-positive malformed flags that can impede debugging. By addressing 12 memory-related and infinite-loop vulnerabilities, the update secures the diagnostic pipeline against malicious capture files. This maintenance cycle highlights the increasing security risks in protocol dissectors as streaming stacks grow more complex and targeted by automated vulnerability discovery. Strategists should note the packaging transition to libexec, which standardizes plugin handling across UN*X environments but may require updates to custom third-party capture tools. Organizations must expedite this update to protect engineering workstations handling untrusted network data. Continued monitoring of the upcoming Wireshark toolchain shifts is recommended for automated DevOps integration.
Additional Context
The Wireshark 4.6 branch, initially released in October 2025, has introduced several performance-critical features for the streaming industry. Per Wireshark Foundation documentation from late 2025, these include on-the-fly capture file compression and a new "Plots" dialog for scatter-plot visualization, which facilitates real-time monitoring of traffic patterns compared to traditional histogram-based I/O graphs. Version 4.6.0 also established a single universal macOS installer for Intel and Apple Silicon, simplifying deployment across diverse hardware environments while phasing out support for legacy drivers like WinPcap in favor of Npcap (per Help Net Security, October 2025). Recent maintenance releases have been heavily influenced by a surge in security reports. Per Cyberpress, May 2026, the Wireshark Foundation has noted a significant increase in AI-assisted vulnerability discovery, leading to dozens of patches for heap overflows and code execution risks in critical protocols like TLS and RDP. In May 2026, version 4.6.6 specifically addressed a critical denial-of-service vulnerability in the ROHC (Robust Header Compression) dissector, which is vital for bandwidth-constrained streaming applications. Development has also focused on emerging security standards, with 4.6 adding initial support for Network Time Security (NTS) decryption and expanding MACsec support (per Wireshark Release Notes, 2026).
Read full article at helpnetsecurity.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source