Impact
The vulnerability arises in the Suricata 8.0.0 through 8.0.6 code that handles app-layer transactions. On flows that are intentionally passed by a pass rule or policy, the parser marks only already-inspected transactions and fails to free completed ones. As a result, each unmarked transaction is rescanned repeatedly, causing the per-flow list to grow without limit and triggering quadratic clean-up costs. This leads to excessive CPU usage and memory consumption, effectively denying service to legitimate traffic. The weakness maps to CWE-401 (Memory Leak) and CWE-407 (Improper Handling of Unchecked Data).
Affected Systems
Open Information Security Foundation’s Suricata engine, versions 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5 are affected; all later releases are not impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate‑to‑high severity. Based on the description, it is inferred that exploitation is feasible over the network; an attacker can craft traffic that triggers pass rules and forces repeated transaction rescans. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the potential for significant service disruption remains high. Once the Exploit conditions are met, the attack can be performed remotely without authentication, leading to a denial of service for any host running the vulnerable Suricata version.
OpenCVE Enrichment