Network Intrusion Detection System Vulnerability in Suricata Software by Open Information Security Foundation
CVE-2026-57222
5.3MEDIUM
What is CVE-2026-57222?
Suricata, a prominent network Intrusion Detection and Prevention System, is susceptible to an issue where crafted IPv4 and IPv6 address pairs can collide within the IPPair hash. This vulnerability arises because the system does not adequately compare the IP address family before reusing the state associated with IPPair. As a result, incorrect detection states may occur, particularly affecting rules that utilize tracking by both IP addresses. The risks associated with this vulnerability can lead to false positives or negatives in network monitoring and protection, jeopardizing overall security. The issue has been resolved in the later versions 8.0.6 and 7.0.17.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6
suricata < 7.0.17 < 7.0.17
