Deadlock in Suricata - CVE-2026-46352
Published: June 3, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to deadlock in IP defragmentation code when processing fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented. A remote attacker can send specially crafted fragmented traffic to cause a denial of service.