Impact
Suricata versions prior to 7.0.17 and 8.0.6 allow a hash collision between IPv4 and IPv6 flow keys when IP family is not compared, causing one protocol's flow state to be reused for the other. This can lead to incorrect flowbit states, traffic detection bypass, or IP-only bypass of security controls.
Affected Systems
The vulnerability impacts the Suricata network IDS/IPS engine developed by the Open Information Security Foundation. All releases before version 7.0.17 and 8.0.6 are affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, but the EPSS score is not available, and the vulnerability is not listed as a known exploited vulnerability in the CISA KEV catalog. The likely attack vector is through network traffic; an attacker could craft packets that trigger the hash collision. No public exploit is documented, so the risk depends on the attacker's ability to send such traffic to a running Suricata instance.
OpenCVE Enrichment