CVE-2026-45769

NameCVE-2026-45769
DescriptionSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeated crafted UDP traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Disable IKE application-layer parsing if it is not needed. Alternatively, use a rule to bypass ike flows after the first packets like `alert ike any any -> any any (sid: 2; flow.pkts_toserver: > 256; bypass; noalert;)`.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
suricata (PTS)trixie1:7.0.10-1+deb13u4vulnerable
forky, sid1:8.0.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
suricatasource(unstable)1:8.0.5-1

Notes

https://github.com/OISF/suricata/security/advisories/GHSA-hg2g-r464-5593
https://redmine.openinfosecfoundation.org/issues/8417 (suricata-7.0.16)
https://redmine.openinfosecfoundation.org/issues/8416 (suricata-8.0.5)
https://github.com/OISF/suricata/commit/97251495e674836693c4636f1eb95fc10b191c15 (suricata-7.0.16)
https://github.com/OISF/suricata/commit/3a6414eb6ae2b2368df51de50e1c1c980109c7a6 (suricata-8.0.5)

Search for package or bug name: Reporting problems