Impact
The vulnerability is a heap out‑of‑bounds read in the SMTP MIME quoted‑printable decoder. When a quoted‑printable escape sequence is split across network traffic chunks and the following chunk contains exactly one byte, Suricata reads one byte past a heap buffer, causing a crash. This results in a denial of service for the event processor rather than direct code execution or data exfiltration.
Affected Systems
The issue affects Suricata versions 7.0.13 through 7.0.17 inclusive. It is present in all builds that enable SMTP MIME quoted‑printable decoding, regardless of other Suricata components.
Risk and Exploitability
With a CVSS score of 8.2, the vulnerability is considered high severity. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, suggesting limited current exploitation. The likely attack vector is crafted SMTP traffic sent across the network, which can trigger the out‑of‑bounds read and crash Suricata when the vulnerable decoder is active.
OpenCVE Enrichment