The following vulnerabilities have been fixed:
wnpa-sec-2026-64 sharkd crash. Issue 21395.
wnpa-sec-2026-65 sharkd crash. Issue 21399.
wnpa-sec-2026-66 UMTS FP protocol dissector crash. Issue 21413.
wnpa-sec-2026-67 RDP protocol dissector crash. Issue 21396.
wnpa-sec-2026-69 Dissection engine reassembly crash. Issue 21423.
wnpa-sec-2026-70 BUSMASTER file parser abnormal exit. Issue 21435.
wnpa-sec-2026-71 Tektronix K12xx file parser crash. Issue 21414.
wnpa-sec-2026-72 ERF file parser crash. Issue 21415.
wnpa-sec-2026-73 Bluetooth Attribute Protocol dissector crash. Issue 21424.
wnpa-sec-2026-74 Catapult DCT2000 file parser crash. Issue 21427.
wnpa-sec-2026-75 C12.22 protocol dissector crash. Issue 21439.
wnpa-sec-2026-76 CMS protocol dissector crash. Issue 21446.
wnpa-sec-2026-77 H.245 protocol dissector crash. Issue 21447.
wnpa-sec-2026-78 Kerberos protocol dissector crash. Issue 21449.
wnpa-sec-2026-79 Bluetooth HFP Profile protocol dissector crash. Issue 21451.
wnpa-sec-2026-80 Bluetooth BR/EDR FHS protocol dissector crash. Issue 21452.
wnpa-sec-2026-81 3gpp phone log file parser crash. Issue 21454.
wnpa-sec-2026-83 CMS protocol dissector crash. Issue 21457, Issue 21458.
wnpa-sec-2026-84 Pcapng file parser crash. Issue 21460.
wnpa-sec-2026-85 SSH protocol dissector crash. Issue 21465.
wnpa-sec-2026-86 ESS protocol dissector crash. Issue 21467.
wnpa-sec-2026-87 X.509IF protocol dissector crash. Issue 21469. CVE-2026-xxx.
wnpa-sec-2026-88 RRC protocol dissector crash. Issue 21478.
wnpa-sec-2026-89 C12.22 protocol dissector crash. Issue 21480.
wnpa-sec-2026-91 Bluetooth AVRCP Profile protocol dissector crash. Issue 21488.
The following bugs have been fixed:
Wireshark Version 4.6.6 - File Capture Properties is excessively slow and hangs Wireshark on Windows. Issue 21337.
Wireshark misdecodes S-NSSAI location validity information IE (5G NAS) Issue 21411.
Wireshark misdecodes NSAG information IE (5G NAS) Issue 21412.
Fuzz job UTF-8 encoding issue: fuzz-2026-07-17-15393056954.pcap. Issue 21419.
Wireshark misdecodes UE security capability IE (5G NAS) Issue 21431.
Wireshark misdecodes Registration wait range IE (5G NAS) Issue 21432.
Wireshark misdecodes Extended CAG information IE (5G NAS) Issue 21433.
Stack buffer overflow in K12/RF5 writer. Issue 21436.
packet-knxip: Secure Wrapper size-offset causes NULL deref / SEGV when decrypting. Issue 21444.
wiretap/rtpdump: swapped caplen/len on truncated samples. Issue 21445.
Sniffer REC_HEADER2 error path over-reads stack buffer. Issue 21461.
Deep NetLog JSON nesting exhausts the native stack. Issue 21462.
androiddump signed btsnoop length causes global out-of-bounds read. Issue 21464.
Wireshark misdecodes SOR transparent container IE (5G NAS) Issue 21472.
Unbounded Daintree timestamp fraction causes signed integer overflow. Issue 21473.
Wireshark misdecodes SOR-CMCI of SOR transparent container IE (5G NAS) Issue 21477.
Wireshark misdecodes Service level AA container (5GSM NAS) Issue 21479.
There are no new protocols in this release.
BT ATT, BT AVRCP, BT BR/EDR RF, BT HFP, C12.22, CMS, ESS, FP, H.245, Kerberos, Rlogin, SSH, X.509AF, and X.509IF
3gpp phone log, Busmaster, Catapult DCT2000, Daintree SNA, Endace ERF, pcapng, RTPDump, Sniffer, and Tektronix K12xx
There is no updated file format support in this release.