Flow State Reuse Vulnerability in Suricata Network Security Engine
CVE-2026-71855
5.9MEDIUM
What is CVE-2026-71855?
In Suricata, prior to versions 7.0.17 and 8.0.6, a vulnerability exists where an IPv4 and IPv6 flow can be incorrectly treated as equal. This occurs due to the lack of comparison between IP families when flow attributes align, allowing an IPv6 packet to erroneously adopt an IPv4 flow state, and vice versa. This misconfiguration can lead to detection bypass or incorrect flowbit state, compromising network monitoring and security functions. It is crucial for users to upgrade to the fixed versions to mitigate these risks.
Affected Version(s)
suricata >= 8.0.0, < 8.0.6 < 8.0.0, 8.0.6
suricata < 7.0.17 < 7.0.17
