Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Incorrect flow state reuse leading to detection bypass
Action: Patch
AI Analysis

Impact

Suricata versions prior to 7.0.17 and 8.0.6 allow a hash collision between IPv4 and IPv6 flow keys when IP family is not compared, causing one protocol's flow state to be reused for the other. This can lead to incorrect flowbit states, traffic detection bypass, or IP-only bypass of security controls.

Affected Systems

The vulnerability impacts the Suricata network IDS/IPS engine developed by the Open Information Security Foundation. All releases before version 7.0.17 and 8.0.6 are affected.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, but the EPSS score is not available, and the vulnerability is not listed as a known exploited vulnerability in the CISA KEV catalog. The likely attack vector is through network traffic; an attacker could craft packets that trigger the hash collision. No public exploit is documented, so the risk depends on the attacker's ability to send such traffic to a running Suricata instance.

Generated by OpenCVE AI on September 19, 2026 at 11:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Suricata to at least version 7.0.17 or 8.0.6 to patch the hash collision issue
  • If Suricata configuration allows, enable strict flow separation per IP family to prevent similar hash collisions
  • Re‑validate IDS rule sets and perform test traffic exercises to ensure flowbit logic differentiates between IPv4 and IPv6 packets after the update

Generated by OpenCVE AI on September 19, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.
Title Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state
Weaknesses CWE-697
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-25T19:22:13.492Z

Reserved: 2026-08-07T18:26:53.523Z

Link: CVE-2026-71855

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:18:08.750

Modified: 2026-09-28T18:39:08.780

Link: CVE-2026-71855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses