Impact
Starting with Suricata 8.0.0 and up to 8.0.4, the LDAP transaction state can collect an unbounded number of responses. Because LDAP traffic can be carried over UDP, crafted packets can force Suricata to allocate excessive memory, resulting in a denial of service. This vulnerability falls under the unbounded resource allocation flaw (CWE‑400) and resource exhaustion (CWE‑770).
Affected Systems
The flaw affects Suricata 8.0.0 through 8.0.4 released by OISF, where LDAP traffic over UDP can acquire an unlimited number of responses within a single transaction.
Risk and Exploitability
With a CVSS score of 7.5, this issue presents a high severity risk. The EPSS score is unavailable and it is not listed in the CISA KEV catalog, yet attackers can exploit it remotely by sending crafted LDAP responses over UDP, with no authentication required, to trigger a denial of service.
OpenCVE Enrichment