Impact
Suricata, an IDS/IPS engine, has a flaw that allows an attacker to send crafted UDP packets that cause the IKEv2 parser to store client transform data without bounds. This leads to arbitrary memory growth in Suricata, which can exhaust available resources and cause the engine to stop responding, resulting in a denial of service.
Affected Systems
Affected systems include Suricata installations using versions earlier than 7.0.16 in the 7.x line or earlier than 8.0.5 in the 8.x line, all distributed by the Open Information Security Foundation.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity; the EPSS score of 1% indicates a low exploitation probability, and the vulnerability is not yet in the CISA KEV catalog. Exploitation requires sending crafted UDP traffic to the Suricata instance, potentially from any remote host, which can cause the engine to exhaust memory and become unresponsive.
OpenCVE Enrichment