Impact
Suricata's FTP parser can allocate a growing list of transactions beyond the configured maximum when processing a large FTP command chunk. The parser then repeatedly processes this oversized list with quadratic complexity, which causes a dramatic increase in CPU usage. An attacker can send specially crafted FTP traffic to force the system into this state, degrading packet processing or potentially exhausting system resources to the point of a denial of service. The vulnerability is classified as CWE-407 and CWE-770, indicating excess resource consumption and large memory allocation weaknesses.
Affected Systems
The flaw exists in Suricata version 8.0.5 only. The FTP parser bug is present in OISF:suricata across all platforms where Suricata is run, but only that specific release is impacted. Versions prior to 8.0.5 or those that have updated to 8.0.6 or later are not affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity vulnerability. The EPSS score of 0.0063 indicates a very low exploitation probability, but the lack of a KEV listing does not mitigate the risk, as the issue is not yet widely recorded. Attackers can trigger the problem remotely by sending crafted FTP traffic from an external network that reaches the Suricata instance. Once triggered, the linear growth of transaction objects causes the engine to enter a state of quadratic CPU consumption, which can be sustained as long as the traffic continues. The impact is limited to the target host, but it can reduce monitoring visibility and lead to denial of service of the detection engine.
OpenCVE Enrichment