Suricata 是一款网络入侵检测系统、入侵防御系统和网络安全监控引擎。在 7.0.16 和 8.0.5 版本之前,IKEv2 解析器在存储客户端转换参数时,其状态可能会无限增长。重复出现的特制 UDP 流量可能导致 Suricata 消耗大量内存,从而引发拒绝服务(DoS)问题。该问题已在 7.0.16 和 8.0.5 版本中修复。同时提供了一些临时解决方案:如果不需要,可以禁用 IKE 应用层解析;或者使用规则在数据包数量超过阈值后绕过 IKE 流量,例如使用规则 。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45764 | 9.1 CRITICAL | Suricata http2: protocol-change type confusion can lead to denial of service |
| CVE-2026-45747 | 7.5 HIGH | Suricata lua/tls: null dereference in TlsGetCertInfo |
| CVE-2026-46387 | 7.5 HIGH | Suricata http2: decompression bomb can cause denial of service in Suricata |
| CVE-2026-45759 | 7.5 HIGH | Suricata http1: quadratic Content-Disposition processing can lead to denial of service |
| CVE-2026-45762 | 7.5 HIGH | Suricata defrag: missing address-family check can lead to remote crash |
| CVE-2026-45765 | 7.5 HIGH | Suricata dnp3: unbounded reassembly can lead to resource exhaustion |
| CVE-2026-45770 | 7.5 HIGH | Suricata lua: excessive flow variable registration can bypass sandbox |
| CVE-2026-45768 | 7.5 HIGH | Suricata ldap: unbounded responses per transaction can lead to resource exhaustion |
| CVE-2026-45766 | 7.5 HIGH | Suricata nfs: unbounded stateful structures can lead to resource exhaustion |
| CVE-2026-45763 | 5.9 MEDIUM | Suricata lua: sandbox allocation limit not enforced for new allocations |
| CVE-2026-45751 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in dotprefix transform |
| CVE-2026-45752 | 5.9 MEDIUM | Suricata detect/transform: use-after-free in decompress transforms |
| CVE-2026-45767 | 4.4 MEDIUM | Suricata datasets: save to absolute filename can be bypassed when combined with load comma |
| CVE-2026-45761 | 3.3 LOW | Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rul |
No comments yet