Suricata 是一个网络入侵检测系统(IDS)、入侵防御系统(IPS)和网络流量安全监控引擎。在 8.0.0 到 8.0.6 版本中,位于 文件中的 函数使用了一个反向的保护逻辑(inverted guard),仅将那些已经检查过的交易标记为“已检查”。当数据流通过“pass 规则”或“pass-the-flow”例外策略时,检测过程被跳过,导致已完成(completed)的交易仍未被标记为已检查,因而永远不会被释放,并被反复重新扫描。这会导致每个数据流的列表无限增长,清理成本呈二次方增长,最终导致 CPU 和
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57228 | 8.2 HIGH | Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder |
| CVE-2026-63447 | 7.5 HIGH | Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption |
| CVE-2026-63452 | 7.5 HIGH | Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption |
| CVE-2026-57227 | 7.5 HIGH | Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages |
| CVE-2026-71418 | 7.5 HIGH | Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption |
| CVE-2026-57223 | 7.0 HIGH | Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalat |
| CVE-2026-57224 | 6.5 MEDIUM | Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhau |
| CVE-2026-63448 | 5.9 MEDIUM | Suricata smb: some SMB flows can cause resource exhaustion |
| CVE-2026-71855 | 5.9 MEDIUM | Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state |
| CVE-2026-57229 | 5.3 MEDIUM | Suricata smtp/mime: incomplete state reset allows detection bypass |
| CVE-2026-57222 | 5.3 MEDIUM | Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6 |
| CVE-2026-63450 | 3.7 LOW | Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection |
| CVE-2026-63449 | 3.7 LOW | Suricata sip: large SIP message bodies can evade detection with frame keyword |
| CVE-2026-57226 | 3.7 LOW | Suricata swf: heap buffer overflow in SWF decompression depth handling |
| CVE-2026-63451 | 3.3 LOW | Suricata detect: frame rules without content and with transform can cause heap buffer over |
| CVE-2026-57225 | 3.3 LOW | Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading |
No comments yet