Impact
Suricata's IP defragmentation logic fails to verify that an existing fragmentation tracker matches the IP address family of an incoming fragment. By sending crafted IPv4 and IPv6 fragmented packets, an attacker can cause an IPv6 fragment to be processed by an IPv4 tracker, leading to a remote packet-triggered crash and denial of service. This flaw, classified as CWE‑843, results in service disruption without giving the attacker wider privileges or data exposure.
Affected Systems
All versions of the Open Information Security Foundation Suricata engine earlier than 7.0.16 or 8.0.5 are vulnerable. The affected product is the Suricata IDS/IPS and Network Security Monitoring engine provided by OISF. No other product branches are known to be impacted. The vulnerability applies to the core defragmentation module that handles both IPv4 and IPv6 traffic.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS is not available, and CISA has not listed the flaw in the KEV catalog, indicating no confirmed widespread exploitation. An attacker would need network access to deliver fragmented packets that trigger the crash; the flaw requires only remote packet delivery and does not provide local privilege escalation or data exfiltration. Until the issue is patched or mitigated, the risk should be considered moderate to high, with the primary impact being service disruption.
OpenCVE Enrichment