Impact
A locally supplied detection rule that combines frame inspection without content and a transformed match without content can trigger a heap buffer overflow during Suricata rule loading. This leads to a crash of the Suricata engine; the vulnerability does not allow remote exploitation through network traffic alone. The flaw falls under a heap-based buffer overflow weakness, and the resulting denial of service can affect the availability of the IDS/IPS monitoring function.
Affected Systems
The vulnerability affects the Open Information Security Foundation's Suricata product, specifically versions 8.0.0 through 8.0.6. Any deployment of Suricata within this version range that processes custom or user-supplied rules is at risk until upgraded to version 8.0.6 or later, where the issue is fixed.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score is not available, suggesting no known exploitation prevalence. The flaw is not listed in CISA KEV catalog. The likely attack vector is the local loading of specially crafted rule files; an attacker with access to the rule repository can trigger the buffer overflow. Network traffic alone cannot reach the flaw, so remote exploitation is not possible. Still, the potential for service disruption exists in environments where rule changes are frequent or automated. The overall risk to availability may increase if rule ingestion is performed without proper validation. Slowness or a complete crash can interrupt traffic analysis, raising the operational impact even though the severity score remains low.
OpenCVE Enrichment