CVE-2026-46352
massRemote denial-of-service deadlock in Suricata 8.0.x IP defragmentation
Suricata versions 8.0.0 through before 8.0.5 contain a deadlock flaw (CWE-833) in the IP defragmentation code that an unauthenticated remote attacker can trigger to hang the engine. The condition occurs when the sensor processes fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented, causing the defragmentation logic to lock up. A successful trigger stalls packet processing, producing a high-availability impact: inline IPS deployments can stop forwarding or inspecting traffic, and monitoring sensors can be blinded. Anyone running an affected Suricata 8.0.x release as an IDS/IPS or NSM engine, including sensors embedded in downstream security products, is affected. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is known; version 8.0.5 contains the fix and no workarounds are available.
What to do: Upgrade all Suricata sensors to version 8.0.5 or later; no workarounds exist, so prioritize perimeter and internet-facing sensors that inspect untrusted traffic. Because the flaw deadlocks rather than crashes the engine, monitor for sensors that stop processing packets or appear hung, which may indicate exploitation attempts. Organizations running Suricata inside third-party appliances should apply vendor updates incorporating the 8.0.5 fix.
| OISF (Open Information Security Foundation) Suricata | >= 8.0.0 and < 8.0.5 (i.e., 8.0.0 through 8.0.4); fixed in 8.0.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented. Version 8.0.5 contains a fix. No known workarounds are available.
- Weakness
- CWE-833
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.