Executive brief
Wireshark, a widely-used network packet analyzer, contains a vulnerability in its Tektronix K12 capture file parser that can cause the application to crash when processing specially crafted capture files. An attacker could exploit this by distributing a malformed packet capture file, causing Wireshark to crash and disrupting network troubleshooting and security analysis activities.
Technical details
The vulnerability is a heap buffer over-read in the K12 file parser (wiretap/k12.c). The get_record() function skips 16-byte file blobs while reading records and adds those skipped bytes to the total_read counter, but does not actually copy them into the buffer. This inflated length value is then passed to process_packet_data(), which attempts to read more data than is actually available in the buffer, causing memcpy() to read beyond the allocated memory boundary. The vulnerability requires no authentication and is triggered by opening a malformed Tektronix K12 .rf5 capture file. The out-of-bounds read results in a heap buffer overflow that crashes the application, achieving denial of service. Patches are available in versions 4.6.8, 4.4.18, and later.
Affected products
- Wireshark Foundation Wireshark 4.6.0 to 4.6.7, 4.4.0 to 4.4.17
Timeline
- 2026-08-12: disclosed
- 2026-08-19: patched: Versions 4.6.8 and 4.4.18 released