Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their packet direction with AppLayerTxData::for_direction(), so a sensor that observes only one direction cannot mark the unseen direction inspected or free completed transactions. The RDP parser in rust/src/rdp/rdp.rs has the same direction-state defect. The per-flow transaction list can grow without bound and cleanup repeatedly scans it, causing increasing CPU and memory consumption and eventual denial of service. This issue is fixed in version 8.0.6.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: resource exhaustion leading to denial of service
Action: Patch
AI Analysis

Impact

Suricata's DHCP parser, and also the RDP parser, incorrectly creates stateless transaction objects without recording packet direction. As a result, any sensor that receives only one side of a DHCP or RDP flow cannot free completed transactions, causing the per‑flow transaction list to grow without bound. The unbounded list forces Suricata to repeatedly scan and consume CPU and memory until the system becomes unresponsive, delivering a denial‑of‑service condition. The weakness is tied to CWE‑400 (Uncontrolled Resource Consumption) and CWE‑770 (Memory Allocation Errors).

Affected Systems

This issue affects the Open Information Security Foundation's Suricata IDS/IPS engine from version 8.0.0 through 8.0.6 inclusive. Systems running any of those releases and processing DHCP or RDP traffic in a directionally constrained manner are vulnerable. The bug is fixed in Suricata 8.0.6, so newer releases are not affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while no EPSS score is available, so the current exploit likelihood cannot be quantified. The vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation. The exploit would require an attacker capable of injecting large volumes of DHCP or RDP packets in a single direction toward a Suricata sensor running a vulnerable version. Such traffic would force the sensor to allocate and retain transaction records until a hard limit is reached, leading to exhaustion of memory and CPU resources and a denial of service to legitimate network monitoring functions. The attack is limited to environments where the sensor cannot see the reverse traffic, so it is most effective against sensors deployed in isolated segments or those configured for unidirectional monitoring.

Generated by OpenCVE AI on September 19, 2026 at 11:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to 8.0.6 or later to apply the fixing changes to the DHCP and RDP parsers.
  • If a prompt upgrade is not possible, restrict or filter DHCP and RDP traffic from reaching the vulnerable sensor to limit unidirectional packet flows.
  • Apply system resource limits (for example, cgroup or container quotas) to the Suricata process to bound CPU and memory usage and prevent a single sensor from exhausting host resources.
  • Continuously monitor Suricata's memory and CPU consumption; if abnormal spikes occur, isolate the sensor or temporarily disable the affected demultiplexer module.

Generated by OpenCVE AI on September 19, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their packet direction with AppLayerTxData::for_direction(), so a sensor that observes only one direction cannot mark the unseen direction inspected or free completed transactions. The RDP parser in rust/src/rdp/rdp.rs has the same direction-state defect. The per-flow transaction list can grow without bound and cleanup repeatedly scans it, causing increasing CPU and memory consumption and eventual denial of service. This issue is fixed in version 8.0.6.
Title Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:22:23.977Z

Reserved: 2026-06-24T02:21:33.811Z

Link: CVE-2026-57224

cve-icon Vulnrichment

Updated: 2026-09-18T20:22:19.203Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:17.780

Modified: 2026-09-28T18:36:45.227

Link: CVE-2026-57224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling