Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63448— Suricata smb: some SMB flows can cause resource exhaustion

Quick assessment

Affected
OISF suricata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Suricata 是一个网络入侵检测系统(IDS)、入侵防御系统(IPS)及网络安全监控引擎。在 7.0.17 和 8.0.6 之前的版本中,SMB 解析器在 Suricata 仅观察到单方向载荷的流(包括异步单侧流)中,可能会保留“强制完成”的事务,因为清理机制会等待未观察到方向的数据检查。 中的事务创建路径可能超出预期的 上限,而清理过程会反复扫描不断增长的列表。因此,持续的单向 SMB 流量可能导致每个流的状态无界增长,进而引发 CPU 和内存耗尽问题。该问题已在 8.0.6 和 7.0.17 版本中修复。

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1041 · Exfiltration Over C2 Channel
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63448

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Suricata smb: some SMB flows can cause resource exhaustion
Source: CVE Program / CVE List V5
Vulnerability Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OISF suricata >= 8.0.0, < 8.0.6 -

II. Public POCs for CVE-2026-63448

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63448

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63448 (4)

Other References for CVE-2026-63448 (4)

Same Patch Batch · OISF · 2026-09-18 · 17 CVEs total

CVE-2026-57228 8.2 HIGH Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder
CVE-2026-63446 7.5 HIGH Suricata app-layer: passed flows can retain transactions, causing resource exhaustion
CVE-2026-63447 7.5 HIGH Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
CVE-2026-63452 7.5 HIGH Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption
CVE-2026-57227 7.5 HIGH Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages
CVE-2026-71418 7.5 HIGH Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption
CVE-2026-57223 7.0 HIGH Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalat
CVE-2026-57224 6.5 MEDIUM Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhau
CVE-2026-71855 5.9 MEDIUM Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state
CVE-2026-57229 5.3 MEDIUM Suricata smtp/mime: incomplete state reset allows detection bypass
CVE-2026-57222 5.3 MEDIUM Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6
CVE-2026-63450 3.7 LOW Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection
CVE-2026-63449 3.7 LOW Suricata sip: large SIP message bodies can evade detection with frame keyword
CVE-2026-57226 3.7 LOW Suricata swf: heap buffer overflow in SWF decompression depth handling
CVE-2026-63451 3.3 LOW Suricata detect: frame rules without content and with transform can cause heap buffer over
CVE-2026-57225 3.3 LOW Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading

IV. Related Vulnerabilities

V. Comments for CVE-2026-63448

No comments yet


Leave a comment