Suricata 是一款网络入侵检测系统(IDS)、入侵防御系统(IPS)以及网络安全监控引擎。在 7.0.17 之前和 8.0.6 之前,当启用非默认的 功能,并且配置了不安全的 (解压深度)时, 中在分配内存时会使用所配置的值,而不是将内存分配限制在 Flash 文件的实际数据需求范围内。因此,一个特制的 SWF 响应可能触发与整数相关的堆缓冲区溢出漏洞,导致 Suricata 崩溃。默认情况下该功能处于禁用状态,且默认深度值不受此漏洞影响。该问题已在 8.0.6 和 7.0.17 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57228 | 8.2 HIGH | Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder |
| CVE-2026-63446 | 7.5 HIGH | Suricata app-layer: passed flows can retain transactions, causing resource exhaustion |
| CVE-2026-63447 | 7.5 HIGH | Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption |
| CVE-2026-63452 | 7.5 HIGH | Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption |
| CVE-2026-57227 | 7.5 HIGH | Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages |
| CVE-2026-71418 | 7.5 HIGH | Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption |
| CVE-2026-57223 | 7.0 HIGH | Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalat |
| CVE-2026-57224 | 6.5 MEDIUM | Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhau |
| CVE-2026-63448 | 5.9 MEDIUM | Suricata smb: some SMB flows can cause resource exhaustion |
| CVE-2026-71855 | 5.9 MEDIUM | Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state |
| CVE-2026-57229 | 5.3 MEDIUM | Suricata smtp/mime: incomplete state reset allows detection bypass |
| CVE-2026-57222 | 5.3 MEDIUM | Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6 |
| CVE-2026-63450 | 3.7 LOW | Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection |
| CVE-2026-63449 | 3.7 LOW | Suricata sip: large SIP message bodies can evade detection with frame keyword |
| CVE-2026-63451 | 3.3 LOW | Suricata detect: frame rules without content and with transform can cause heap buffer over |
| CVE-2026-57225 | 3.3 LOW | Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading |
No comments yet