ZeroHour

CVE-2026-46352

mass

Remote denial-of-service deadlock in Suricata 8.0.x IP defragmentation

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

Suricata versions 8.0.0 through before 8.0.5 contain a deadlock flaw (CWE-833) in the IP defragmentation code that an unauthenticated remote attacker can trigger to hang the engine. The condition occurs when the sensor processes fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented, causing the defragmentation logic to lock up. A successful trigger stalls packet processing, producing a high-availability impact: inline IPS deployments can stop forwarding or inspecting traffic, and monitoring sensors can be blinded. Anyone running an affected Suricata 8.0.x release as an IDS/IPS or NSM engine, including sensors embedded in downstream security products, is affected. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is known; version 8.0.5 contains the fix and no workarounds are available.

What to do: Upgrade all Suricata sensors to version 8.0.5 or later; no workarounds exist, so prioritize perimeter and internet-facing sensors that inspect untrusted traffic. Because the flaw deadlocks rather than crashes the engine, monitor for sensors that stop processing packets or appear hung, which may indicate exploitation attempts. Organizations running Suricata inside third-party appliances should apply vendor updates incorporating the 8.0.5 fix.

Affected
OISF (Open Information Security Foundation) Suricata>= 8.0.0 and < 8.0.5 (i.e., 8.0.0 through 8.0.4); fixed in 8.0.5
Estimated exposure
mass≈100,000–1,000,000+ sensor deployments (widely used open-source IDS/IPS engine) — Suricata is one of the dominant open-source IDS/IPS/NSM engines, deployed on enterprise perimeter sensors and bundled into numerous commercial firewalls and NSM platforms that inspect internet-bound traffic, so the sensor install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented. Version 8.0.5 contains a fix. No known workarounds are available.

Weakness
CWE-833
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.