PT-2026-4981 · Open Information Security Foundation · Suricata

Xiangwei Zhang

·

Published

2026-01-01

·

Updated

2026-03-10

·

CVE-2026-22258

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 8.0.3 Suricata versions prior to 7.0.14
Description Suricata is a network IDS, IPS and NSM engine. Crafted DCERPC traffic can cause Suricata to expand a buffer without limits, leading to memory exhaustion and process termination. While initially reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also affected. DCERPC/TCP in the default configuration should not be vulnerable as the default stream depth is limited to 1MiB.
Recommendations For Suricata versions prior to 8.0.3, apply the patch available in version 8.0.3. For Suricata versions prior to 7.0.14, apply the patch available in version 7.0.14. For DCERPC/UDP, disable the parser. For DCERPC/TCP, limit the stream.reassembly.depth setting. For DCERPC/SMB, limit the stream.reassembly.depth setting, noting that this may lead to loss of visibility in SMB.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-00955
CVE-2026-22258
GHSA-289C-H599-3XCX
OPENSUSE-SU-2026:10082-1

Affected Products

Suricata