Denial of Service Risk in Suricata Network Security Monitoring Engine
CVE-2026-57224
6.5MEDIUM
What is CVE-2026-57224?
Suricata, a widely used network Intrusion Detection and Prevention System, is affected by a vulnerability in its DHCP and RDP parsers, where transactions are created without proper state management regarding packet direction. This oversight can lead to an unbounded growth of per-flow transaction lists, causing increasing CPU and memory utilization, potentially resulting in a denial of service. Users are advised to upgrade to version 8.0.6 or later to mitigate these issues.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6
