Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Patch Immediately
AI Analysis

Impact

Suricata’s SMB parser can retain force‑completed transactions on flows where data is seen in only one direction. Because cleanup waits for inspection in the unseen direction, transaction creation can exceed the intended SMB_MAX_TX bound, and the cleanup routine repeatedly scans the growing list. Sustained one‑directional SMB traffic can therefore cause unbounded per‑flow state, leading to high CPU usage and memory exhaustion. This flaw is an example of uncontrolled resource consumption (CWE‑400).

Affected Systems

OISF Suricata, versions prior to 7.0.17 and 8.0.6, is impacted because the SMB parser logic was unchanged. The fix was applied in the 7.0.17 and 8.0.6 releases.

Risk and Exploitability

The CVSS score of 5.9 classifies the issue as moderate severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, indicating low current exploitation activity. Attackers can trigger the flaw by generating sustained one‑direction SMB traffic, which can be sent remotely from a compromised host or a malicious actor on the network. The resource exhaustion can degrade overall network monitoring performance or exhaust a monitored host, enabling opportunistic attacks or a denial‑of‑service condition.

Generated by OpenCVE AI on September 19, 2026 at 11:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Suricata 7.0.17 or later, or to 8.0.6 or later, to apply the official fix.
  • Until upgrade, block or rate‑limit one‑sided SMB traffic at the network perimeter to reduce the impact of the unbounded transaction list.
  • Disable the SMB detection engine if SMB traffic is not required, or reduce its activity through configuration changes.

Generated by OpenCVE AI on September 19, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload in only one direction, including async-oneside flows, because cleanup waits for inspection in the unseen direction. The transaction creation paths in rust/src/smb can exceed the intended SMB_MAX_TX bound, and cleanup repeatedly scans the growing list. Sustained one-directional SMB traffic can therefore cause unbounded per-flow state and CPU and memory exhaustion. This issue is fixed in versions 8.0.6 and 7.0.17.
Title Suricata smb: some SMB flows can cause resource exhaustion
Weaknesses CWE-400
CWE-401
CWE-407
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:48:51.877Z

Reserved: 2026-07-16T19:35:57.767Z

Link: CVE-2026-63448

cve-icon Vulnrichment

Updated: 2026-09-22T15:48:45.595Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:17:04.060

Modified: 2026-09-28T18:33:31.947

Link: CVE-2026-63448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-407

    Inefficient Algorithmic Complexity