CVE-2026-57224
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 18, 2026 · Last modified: Sep 18, 2026 · CWE-400 · CWE-770
Not enough EPSS history yet.
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their packet direction with AppLayerTxData::for_direction(), so a sensor that observes only one direction cannot mark the unseen direction inspected or free completed transactions. The RDP parser in rust/src/rdp/rdp.rs has the same direction-state defect. The per-flow transaction list can grow without bound and cleanup repeatedly scans it, causing increasing CPU and memory consumption and eventual denial of service. This issue is fixed in version 8.0.6.
- github.comhttps://github.com/OISF/suricata/commit/3f86c56c800392ede5cfaf7a944a431fd8445c55
- github.comhttps://github.com/OISF/suricata/commit/5af13e3eb06be0387da8703b611c5ce932245c59
- github.comhttps://github.com/OISF/suricata/commit/bac8a69ca48c14582d39a244a87edad44751ebe1
- github.comhttps://github.com/OISF/suricata/commit/ef035c7603293a10c5ad087e3d20b05f75236144
- github.comhttps://github.com/OISF/suricata/pull/15740
- github.comhttps://github.com/OISF/suricata/releases/tag/suricata-8.0.6
- github.comhttps://github.com/OISF/suricata/security/advisories/GHSA-m2vc-g65c-ph7m
- redmine.openinfosecfoundation.orghttps://redmine.openinfosecfoundation.org/issues/8621