Memory Consumption Issue in Suricata Network Security Monitoring Engine
CVE-2026-45769
7.5HIGH
What is CVE-2026-45769?
The Suricata network security monitoring engine has a vulnerability that allows the IKEv2 parser state to grow without bounds when handling crafted UDP traffic. This can lead to excessive memory consumption, potentially resulting in a denial of service. To mitigate this issue, users are encouraged to upgrade to Suricata versions 7.0.16 or 8.0.5, which address the vulnerability. Alternatively, if the IKE application-layer parsing is not essential, it can be disabled. As a workaround, users can implement a rule to bypass IKE flows after the initial packets to manage memory usage effectively.
Affected Version(s)
suricata >= 8.0.0, < 8.0.5 < 8.0.0, 8.0.5
suricata < 7.0.16 < 7.0.16
