ZeroHour

CVE-2026-45766

mass

Unbounded memory growth in Suricata NFS parser enables remote DoS

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

Suricata versions before 7.0.16 and 8.0.5 contain an uncontrolled resource-consumption flaw (CWE-400, CWE-770) in the state structures of its NFS application-layer parser, which are insufficiently bounded. An attacker who can send crafted NFS traffic across a network segment monitored by Suricata can drive the engine to consume excessive memory. Successful abuse results in denial of service of the monitoring sensor, with no confidentiality or integrity impact (CVSS 3.1 7.5, availability-only, network-exploitable without privileges or user interaction). Anyone running an affected Suricata version with NFS application-layer parsing enabled is affected, including sensors embedded in firewalls and network detection appliances. Exploitation has not been reported: the flaw is not in CISA's KEV and no public proof-of-concept is known.

What to do: Upgrade to Suricata 7.0.16 or 8.0.5, matching your deployed series. Where an immediate upgrade is not possible, disable NFS application-layer parsing on sensors that do not need to inspect NFS traffic. Prioritize sensors monitoring traffic to NFS servers (e.g., port 2049) and check for abnormal sensor memory growth as an indicator of attempted abuse.

Affected
OISF (Open Information Security Foundation) Suricataall versions prior to 7.0.16 and prior to 8.0.5; fixed in 7.0.16 (7.x series) and 8.0.5 (8.x series)
Estimated exposure
mass≈100,000+ deployed sensors worldwide (direct open-source installs plus bundled firewall/appliance deployments); the directly exposed subset is sensors… — Suricata is one of the dominant open-source IDS/IPS engines and is commonly bundled as a package/plugin in open-source firewall distributions and embedded in numerous commercial network-detection appliances, implying an aggregate install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS application-layer parsing if it is not needed.

Weakness
CWE-400, CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.