Wireshark 4.6.8 Fixes 28 Vulnerabilities, Including Nine File‑Parser Bugs That Could Allow Remote Code Execution via Malicious Capture Files
What Happened — Wireshark 4.6.8 addresses 28 security bugs, nine of which reside in file‑parser modules that process saved capture files (pcapng, Endace ERF, Tektronix K12xx, etc.). An attacker who can deliver a crafted capture file can trigger crashes or potentially execute code on the analyst’s workstation without ever touching the network.
Why It Matters for Compliance & Audit Readiness
- The flaws illustrate a classic control‑gap: reliance on unpatched third‑party tools to ingest external data. SOC 2 continuous‑compliance programs require documented patch‑management and evidence that file‑handling controls are in place.
- Demonstrating that you monitor vendor advisories (e.g., Wireshark’s wnpa‑sec‑2026‑64 to 91) and apply updates promptly supplies audit‑ready evidence for the System Security and Change Management criteria.
- Mapping these vulnerabilities to your control framework (e.g., NIST 800‑53 SC‑7, ISO 27001 A.12.1) and capturing remediation tickets satisfies the Control Mapping capability in Verisq’s Trust Center.
Who Is Affected — Organizations that use Wireshark or any downstream tooling that parses capture files: network operations centers, security operations centers, telecom equipment vendors, and any enterprise that conducts packet‑level troubleshooting.
Recommended Actions
- Inventory all endpoints running Wireshark and verify they are upgraded to 4.6.8 or later.
- Incorporate Wireshark advisory monitoring into your continuous‑risk dashboard; treat each advisory as a control‑testing item.
- Document the patch‑application process (ticket, approval, verification) to satisfy SOC 2 evidence requirements.
Technical Notes
- Attack vector: malicious capture file opened locally; exploits stem from memory‑safety bugs (stack buffer overflow, out‑of‑bounds reads, stack exhaustion).
- No public CVE IDs were assigned; advisories are tracked as wnpa‑sec‑2026‑64 through wnpa‑sec‑2026‑91.
- Affected parsers include pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Catapult DCT2000, Gammu DCT3, 3GPP phone logs, TTX Logger, and Windows‑only Ixia IxVeriWave/Vector Inform‑atik BLF.
Source: Help Net Security – Wireshark 4.6.8 patches 28 security bugs