Wireshark released version 4.6.5 to remediate more than 40 vulnerabilities, including multiple flaws that could allow arbitrary code execution when the tool processes malformed network packets or malicious capture and profile files. The most severe issues were reported in the TLS dissector, SBC codec, RDP dissector, and profile import functionality, where crashes may be exploitable for code execution.
The release also fixes a broad set of denial-of-service bugs across numerous protocol dissectors, several infinite-loop conditions that can stall unattended analysis workflows, and decompression-related crashes in zlib and LZ77 handling. Because Wireshark is widely deployed in enterprise security operations, packet analysis, and SIEM-connected environments—sometimes with elevated privileges—the patched version is being treated as a high-priority security update.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Wireshark released version 4.6.5 to address more than 40 security flaws, including vulnerabilities that could allow arbitrary code execution via malformed packets or malicious capture/profile files. The fixes also covered numerous denial-of-service issues, infinite-loop bugs, and decompression-related crashes affecting multiple protocol dissectors and engine components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcelists.debian.org
Open sourceisc.sans.edu
Open sourcecybersecuritynews.com
Open sourceerrata.rockylinux.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.