Impact
Suricata's DHCP parser, and also the RDP parser, incorrectly creates stateless transaction objects without recording packet direction. As a result, any sensor that receives only one side of a DHCP or RDP flow cannot free completed transactions, causing the per‑flow transaction list to grow without bound. The unbounded list forces Suricata to repeatedly scan and consume CPU and memory until the system becomes unresponsive, delivering a denial‑of‑service condition. The weakness is tied to CWE‑400 (Uncontrolled Resource Consumption) and CWE‑770 (Memory Allocation Errors).
Affected Systems
This issue affects the Open Information Security Foundation's Suricata IDS/IPS engine from version 8.0.0 through 8.0.6 inclusive. Systems running any of those releases and processing DHCP or RDP traffic in a directionally constrained manner are vulnerable. The bug is fixed in Suricata 8.0.6, so newer releases are not affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while no EPSS score is available, so the current exploit likelihood cannot be quantified. The vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation. The exploit would require an attacker capable of injecting large volumes of DHCP or RDP packets in a single direction toward a Suricata sensor running a vulnerable version. Such traffic would force the sensor to allocate and retain transaction records until a hard limit is reached, leading to exhaustion of memory and CPU resources and a denial of service to legitimate network monitoring functions. The attack is limited to environments where the sensor cannot see the reverse traffic, so it is most effective against sensors deployed in isolated segments or those configured for unidirectional monitoring.
OpenCVE Enrichment