Impact
Suricata is a network IDS/IPS that parses Network File System traffic. An unbounded stateful structure within its NFS parser can be exploited with crafted packets; the parser allocates memory without proper limits, allowing an attacker to saturate Suricata's service that eliminates the IDS functionality for a user of the vulnerable Suricata instance. This flaw is expressed as resource exhaustion (CWE‑400) and improper memory allocation (CWE‑770).
Affected Systems
The issue affects the open‑source Suricata engine maintained by the Open Information Security Foundation. All builds prior to Suricata 7.0.16 and 8.0.5 are vulnerable. Those versions parse NFS traffic until an update is applied.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity and the lack of an EPSS score means the current exploitation probability is unknown; it is also not listed in the CISA KEV catalog. The vulnerability is network‑based, requiring an attacker to send malformed NFS packets over the wire, so remote attackers can exploit it without needing local access or administrative privileges. The resultant denial of service can shut down Suricata for all monitored hosts, demonstrating a clear and critical availability impact.
OpenCVE Enrichment