Pcap-Triage

On November 19, 2025, Wireshark 4.6.1 and 4.4.11 shipped fixes for BPv7 and Kafka dissector crashes. Here’s the IR-ready rundown, what to...

Wireshark 4.6.1: patch your DFIR workstations—two dissector crash bugs fixed

4n6 Beat
3 min read

Wireshark 4.6.1 and 4.4.11 shipped on November 19, 2025 with fixes for two dissector crash issues; installers for Windows and macOS plus source are available now (Wireshark news). The patched issues are BPv7 (Bundle Protocol v7) and Kafka dissectors that could crash when parsing crafted traffic or trace files (wnpa-sec-2025-05, wnpa-sec-2025-06). Wireshark notes discovery during internal testing and no known in-the-wild exploitation, but a crash during triage still means lost analyst time and potentially missed signal (BPv7 advisory, Kafka advisory). The 4.6.1 release is also the first maintenance for the 4.6 branch (4.6.1 release notes).