Incorrect Comparison in Suricata - CVE-2026-57222
Published: July 22, 2026
Suricata
Detailed vulnerability description
The vulnerability allows a remote attacker to cause incorrect state reuse across IPv4 and IPv6 address pairs.
The vulnerability exists due to incorrect comparison in IPPair-backed state handling when processing crafted IPv4 and IPv6 address pairs. A remote attacker can send crafted traffic to cause incorrect state reuse across IPv4 and IPv6 address pairs.
This affects xbits track ip_pair, app-layer expectations such as FTP data expectations, and in 7.0.x also thresholding, detection_filter, rate_filter using track by_both.