Impact
Suricata processes DNS-over-HTTP/2 traffic. A flaw in the Rust implementation keeps earlier DATA frame payloads in an internal buffer rather than clearing them. When an attacker sends multiple DATA frames with the EndOfStream flag, the buffer can grow to its 65 KiB limit and the engine re‑processes all prior contents on each new frame. This quadratic CPU usage can stall packet processing, cause loss of monitoring visibility and ultimately lead to a denial of service. The weakness is categorized as CWE‑407, unsafe recursion/iteration that results in uncontrolled resource consumption.
Affected Systems
OISF Suricata versions 8.0.0 through 8.0.6. The issue was fixed in release 8.0.6. All earlier releases in the 8.0.x series are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact. EPSS is not available, so current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. A likely attack vector is network‑based; an attacker can trigger the exploit by sending crafted HTTP/2 DATA frames to a Suricata deployment over the Internet or an internal network. The vulnerability requires no local privileges or authentication and therefore can affect any host running the vulnerable Suricata version.
OpenCVE Enrichment