Wireshark 4.6.5 released

The update of the network analysis tool fixes numerous security vulnerabilities.

Wireshark version 4.6.5 is a major security update that significantly improves the stability and safety of the tool. Given the number and severity of the fixed vulnerabilities, updating promptly is strongly advised to reduce exposure to potential attacks.

The newly released Wireshark version 4.6.5 addresses a wide range of security vulnerabilities that previously exposed the network analysis tool to potential attacks. If exploited, these flaws could allow attackers to crash systems (Denial of Service) or, in more critical cases, execute malicious code on affected machines. To mitigate these risks, the developers have provided updated, secure versions and recommend users upgrade without delay.

DoS and Malicious Code Vulnerabilities

According to the official changelog, most of the fixed vulnerabilities are classified as medium severity, such as CVE-2026-6520, which could be exploited to trigger DoS conditions, for example through issues in the OpenFlow v6 protocol that may lead to system crashes.

Several high-severity vulnerabilities (including CVE-2026-5402, CVE-2026-5403, CVE-2026-5405, and CVE-2026-5656) could enable attackers to inject and execute malicious code, potentially compromising entire systems. Although there are currently no known cases of these vulnerabilities being actively exploited, the risks are significant enough that administrators and users should apply the updates as soon as possible.

The update includes security fixes and bug corrections across numerous protocol dissectors and internal components. Many of these vulnerabilities involve crashes, infinite loops, memory corruption, or parsing errors in protocols such as TLS, SMB2, RDP, HTTP, OpenFlow, ZigBee, WebSocket, and many others. Some issues could also lead to heap overflows, buffer overflows, or memory leaks, further increasing the attack surface.

The high number of reported vulnerabilities is partly attributed to a recent increase in AI-assisted vulnerability discovery, which has improved the detection of previously unnoticed flaws.

The update also resolves various functional bugs, including build issues, crashes in specific environments, incorrect protocol parsing, UI inconsistencies, and problems with external tools or integrations.

about author