Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash because src/ippair.c did not compare the IP address family before reusing IPPair-backed state. This can apply state from one IP family to another for xbits track ip_pair, FTP data expectations, and, on the 7.0 release line, thresholding, detection_filter, and rate_filter rules using track by_both, causing incorrect detection state. This issue is fixed in versions 8.0.6 and 7.0.17.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect Intrusion Detection State Reuse
Action: Apply Patch
AI Analysis

Impact

A hash collision in Suricata’s IPPair module can cause a crafted IPv4 and IPv6 address pair to produce identical hash values, leading Suricata to reuse state that was originally associated with one IP family for the other. This flaw disrupts the integrity of detection state for features such as xbits track ip_pair, FTP data expectations, and, on the 7.0 release line, thresholding, detection_filter, and rate_filter rules that use track by_both. The resulting incorrect detection state may cause legitimate traffic to be missed or false alerts to be generated, compromising detection accuracy and potentially enabling traffic to evade detection.

Affected Systems

The vulnerability affects the open-source Suricata network security engine developed by OISF. Versions earlier than 7.0.17 and 8.0.6 are impacted; all newer releases contain the fix.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. Exploitation is feasible by sending specially crafted packets that trigger the hash collision, which could be performed remotely against the Suricata instance if network visibility is available. No evidence of exploitation is reported in the CISA KEV catalog and the exploit probability (EPSS) is currently unavailable. Attackers rely on crafting traffic that causes state reuse across IPv4 and IPv6 families, potentially leading to detection bypasses or false alerts.

Generated by OpenCVE AI on September 19, 2026 at 10:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 7.0.17 or 8.0.6 or later to apply the fixed IPPair hash comparison logic.
  • If immediate upgrade is not possible, mitigate by disabling or restructuring rules that rely on IPPair state, such as xbits track ip_pair, FTP data expectations, and by_both-based thresholds, filters, or rate limits, to avoid the vulnerable state reuse.
  • Continuously monitor Suricata logs for anomalous state handling or detection inconsistencies and update configurations or scripts to isolate traffic that could trigger hash collisions.

Generated by OpenCVE AI on September 19, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash because src/ippair.c did not compare the IP address family before reusing IPPair-backed state. This can apply state from one IP family to another for xbits track ip_pair, FTP data expectations, and, on the 7.0 release line, thresholding, detection_filter, and rate_filter rules using track by_both, causing incorrect detection state. This issue is fixed in versions 8.0.6 and 7.0.17.
Title Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6
Weaknesses CWE-697
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T16:22:19.565Z

Reserved: 2026-06-24T02:21:33.810Z

Link: CVE-2026-57222

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:14.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:17.613

Modified: 2026-09-29T12:48:22.847

Link: CVE-2026-57222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses