Impact
Suricata's MQTT parser allows an attacker to send repeated PUBREC or PUBREL messages that are appended to a transaction without any limit. This behavior can cause the processor to allocate increasingly large amounts of memory and CPU time for each transaction. The impact is a significant degradation of performance and eventual denial of service when the system runs out of resources. The vulnerability stems from improper resource limits (CWE-400) and improper handling of growing data structures (CWE-770).
Affected Systems
The issue affects any installation of OISF Suricata from version 7.0.0 through 7.0.16 and from 8.0.0 through 8.0.5. Versions 7.0.17 and 8.0.6 include the fix and are not susceptible.
Risk and Exploitability
With a CVSS score of 7.5, this vulnerability is categorized as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker forging MQTT control messages to a network component where Suricata is operating, allowing remote or local exploitation depending on exposure. Successful exploitation would cause the Suricata engine to consume excessive CPU and memory, slowing or stopping packet inspection and potentially leading to a broader denial of service for monitored traffic.
OpenCVE Enrichment