Hi, Thanks for the report. Wireshark has its own implementation of the PcapNg format, so it's not unexpected that it behaves differently than tcpdump.
The fix is a bit too intrusive for a stable update, especially for a minor bug like this. I will simply do a buster backport of libpcap 1.9.1-2 from bullseye. Can you share your modified test file? Thanks.