Impact
Suricata’s IP defragmentation logic can deadlock when it processes fragmented traffic that contains an encapsulated tunnel protocol whose own payload is also fragmented. The deadlock occurs during the defragmentation phase and causes the Suricata process to hang, resulting in a loss of detection and prevention services. This weakness is classified as CW 833, a deadlock condition.
Affected Systems
The affected installations are OISF Suricata versions 8.0.0 through 8.0.4 inclusive. Any environment that relies on Suricata for network intrusion detection, prevention, or security monitoring and runs one of these unpatched versions is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact on availability. The EPSS score is reported as <1%, meaning the likelihood of exploitation in the wild is very low at present, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker would need to craft traffic that includes a fragmented tunnel (such as GRE or IPIP) with a fragmented payload so that Suricata’s defragmentation routine enters the deadlock state. Once the deadlock occurs, the Suricata process ceases to function until restarted, which can be observed as a halt in detection output or a crash placeholder.
OpenCVE Enrichment