Impact
Suricata is a network IDS/IPS that parses Network File System traffic. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. The flaw is captured by CWE-400 and CWE-770.
Affected Systems
The issue affects the open‑source Suricata engine maintained by the Open Information Security Foundation. All builds prior to Suricata 7.0.16 and 8.0.5 are vulnerable. Those versions parse NFS traffic until an update is applied.
Risk and Exploitability
The CVSS base score of 7.5 indicates that exploitation probability is uncertain because no EPSS score is available; it is also not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending malformed NFS packets over the wire, an inference drawn from the description that Suricata parses NFS traffic until a fix is applied, which implies that such traffic can trigger the memory exhaustion. The resultant denial of service can demonstrate a clear and critical availability impact.
OpenCVE Enrichment