Impact
A hash collision in Suricata’s IPPair module can cause a crafted IPv4 and IPv6 address pair to produce identical hash values, leading Suricata to reuse state that was originally associated with one IP family for the other. This flaw disrupts the integrity of detection state for features such as xbits track ip_pair, FTP data expectations, and, on the 7.0 release line, thresholding, detection_filter, and rate_filter rules that use track by_both. The resulting incorrect detection state may cause legitimate traffic to be missed or false alerts to be generated, compromising detection accuracy and potentially enabling traffic to evade detection.
Affected Systems
The vulnerability affects the open-source Suricata network security engine developed by OISF. Versions earlier than 7.0.17 and 8.0.6 are impacted; all newer releases contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Exploitation is feasible by sending specially crafted packets that trigger the hash collision, which could be performed remotely against the Suricata instance if network visibility is available. No evidence of exploitation is reported in the CISA KEV catalog and the exploit probability (EPSS) is currently unavailable. Attackers rely on crafting traffic that causes state reuse across IPv4 and IPv6 families, potentially leading to detection bypasses or false alerts.
OpenCVE Enrichment