Impact
Suricata’s SMB parser can retain force‑completed transactions on flows where data is seen in only one direction. Because cleanup waits for inspection in the unseen direction, transaction creation can exceed the intended SMB_MAX_TX bound, and the cleanup routine repeatedly scans the growing list. Sustained one‑directional SMB traffic can therefore cause unbounded per‑flow state, leading to high CPU usage and memory exhaustion. This flaw is an example of uncontrolled resource consumption (CWE‑400).
Affected Systems
OISF Suricata, versions prior to 7.0.17 and 8.0.6, is impacted because the SMB parser logic was unchanged. The fix was applied in the 7.0.17 and 8.0.6 releases.
Risk and Exploitability
The CVSS score of 5.9 classifies the issue as moderate severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, indicating low current exploitation activity. Attackers can trigger the flaw by generating sustained one‑direction SMB traffic, which can be sent remotely from a compromised host or a malicious actor on the network. The resource exhaustion can degrade overall network monitoring performance or exhaust a monitored host, enabling opportunistic attacks or a denial‑of‑service condition.
OpenCVE Enrichment