CVE-2026-63448

NameCVE-2026-63448
DescriptionSuricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
suricata (PTS)trixie1:7.0.10-1+deb13u4vulnerable
forky, sid1:8.0.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
suricatasource(unstable)1:8.0.6-1

Notes

https://github.com/OISF/suricata/security/advisories/GHSA-hvvj-c8xx-9g35
Fixed by: https://github.com/OISF/suricata/commit/755d6c3061de4d7ba97f0ed31cdc17ab8cab4476 (suricata-8.0.6)
Fixed by: https://github.com/OISF/suricata/commit/9a54a043516e644bb7b9d34117a91977f950a281 (suricata-8.0.6)
Fixed by: https://github.com/OISF/suricata/commit/88adab8bd3d62912941647ab65032d5ec75c893a (suricata-7.0.17)
Fixed by: https://github.com/OISF/suricata/commit/bc39274a638d1cca2391cfa4891c8b6c255ff9ce (suricata-7.0.17)

Search for package or bug name: Reporting problems