Impact
Suricata’s inspection‑buffer helper can leave a pointer to freed memory when a chained dotprefix transform causes the backing buffer to be reallocated. The flaw can be triggered during normal network traffic processing and requires a specific, non‑malicious rule. The dangling pointer could allow an attacker to manipulate the processed data or cause a crash, potentially impacting availability and integrity of the system.
Affected Systems
The vulnerability affects Suricata releases before 7.0.16 and before 8.0.5. It is present in all other versions of the OISF Suricata IDS/IPS engine that rely on the same inspection‑buffer helper logic.
Risk and Exploitability
The CVSS score of 5.9 places this weakness in the moderate range. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Exploitation requires crafted network traffic and a specific rule set; the attack vector is likely over the network when rule processing occurs. The knowledge base warns that only certain chained dotprefix transformations will trigger the problem, making spontaneous exploitation less likely but still possible in a controlled environment.
OpenCVE Enrichment