SB2026092210 - Multiple vulnerabilities in Suricata



SB2026092210 - Multiple vulnerabilities in Suricata

Published: September 22, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092210
CSH Severity
High
Patch available
YES
Number of vulnerabilities 12
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 17% Medium 42% Low 42%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 12 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-94084)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error during header inspection. A remote attacker can execute arbitrary code on the target system.


2) Type Confusion (CVE-ID: CVE-2026-94083)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error when an h2c upgrade is followed by a DoH2 request. A remote attacker can pass specially crafted data to the application, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


3) Improper Output Neutralization for Logs (CVE-ID: N/A)

CWE-ID: CWE-117 - Improper Output Neutralization for Logs

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to corrupt PostgreSQL event and alert records.

The vulnerability exists due to improper output neutralization for logs in PostgreSQL EVE JSON logging when processing crafted backend responses ending in a ParameterStatus message. A remote attacker can send a crafted backend response to corrupt PostgreSQL event and alert records.

Unbalanced EVE JSON can disrupt downstream log processing.


4) Improper handling of exceptional conditions (CVE-ID: N/A)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to limit RDP visibility.

The vulnerability exists due to improper handling of exceptional conditions in the RDP application-layer parser when processing a crafted MCS/CS message. A remote attacker can send a crafted MCS/CS message to cause RDP parsing in one direction of an affected flow to stop making progress.

Later RDP transactions in the affected direction are not decoded or logged, while raw stream inspection and packet-processing threads remain active.


5) Always-Incorrect Control Flow Implementation (CVE-ID: N/A)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass FTP-specific inspection and enforcement.

The vulnerability exists due to always-incorrect control flow implementation in the FTP application-layer parser when processing an overlong FTP command or reply followed by a complete FTP line in the same stream slice. A remote attacker can send a crafted FTP control line sequence to bypass FTP-specific inspection and enforcement.

Raw stream inspection remains active, but FTP data-channel recognition, file extraction, and filestore may be bypassed.


6) Improper Handling of Length Parameter Inconsistency (CVE-ID: N/A)

CWE-ID: CWE-130 - Improper Handling of Length Parameter Inconsistency

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass PostgreSQL response inspection.

The vulnerability exists due to improper handling of length parameter inconsistency in the PostgreSQL response parser when processing malformed RowDescription or DataRow responses. A remote attacker can send a malformed PostgreSQL server response to bypass PostgreSQL response inspection.

Only deployments with PostgreSQL parsing enabled are affected. Raw stream inspection and packet forwarding continue.


7) Use-after-free (CVE-ID: N/A)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to execute arbitrary code or cause a denial of service.

The vulnerability exists due to a use-after-free in lua/hashlib hash objects when matching traffic executes a malicious Lua rule script. A local privileged user can invoke __gc on an MD5, SHA-1, or SHA-256 object and then reuse it to execute arbitrary code or cause a denial of service.

Network traffic alone cannot trigger the issue without a malicious rule script.


8) Interpretation Conflict (CVE-ID: N/A)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass ssh.hassh* detection and cause hassh fields to be omitted from EVE output.

The vulnerability exists due to an interpretation conflict in Suricata's SSH hassh inspection parser when processing crafted SSH traffic containing an oversized incomplete KEXINIT record. A remote attacker can send a crafted SSH record to desynchronize parsing for one flow direction and bypass ssh.hassh* detection.

Only subsequent records in the affected flow direction are impacted.


9) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in Suricata's per-thread decision cache when processing high-cardinality traffic matching IPv4 signatures configured with source- or destination-tracked limit or both thresholds. A remote attacker can send high-cardinality traffic to exhaust memory and terminate Suricata.

In inline deployments, traffic forwarding may be interrupted.


10) Improper handling of highly compressed data (CVE-ID: N/A)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in the HTTP/1 and HTTP/2 Brotli body decoder when processing crafted cleartext or decrypted HTTP requests. A remote attacker can send a Brotli-encoded request body that forces large decoder memory allocations to cause a denial of service.

HTTP parsing is enabled by default.


11) Always-Incorrect Control Flow Implementation (CVE-ID: N/A)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass LDAP application-layer inspection for an affected TCP flow.

The vulnerability exists due to incorrect control flow implementation in LDAP app-layer inspection when resynchronizing after a TCP reassembly gap. A remote attacker can send TCP traffic containing a reassembly gap followed by data that cannot immediately be parsed as a complete LDAP message to bypass LDAP application-layer inspection for an affected TCP flow.

Raw payload and stream inspection remain active, and UDP LDAP is unaffected.


12) Unchecked Return Value (CVE-ID: N/A)

CWE-ID: CWE-252 - Unchecked Return Value

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass the configured app-layer error exception policy.

The vulnerability exists due to an unchecked return value in the IKEv1 parser when processing crafted IKEv1 traffic. A remote attacker can send a malformed IKEv1 datagram to bypass the configured app-layer error exception policy.

The bypass is limited to the malformed datagram or flow; later valid IKE datagrams and raw packet or payload inspection remain available.


Remediation

Install update from vendor's website.