Incorrect Comparison in Suricata - CVE-2026-71855

 

Incorrect Comparison in Suricata - CVE-2026-71855

Published: August 20, 2026


Vulnerability identifier: #VU144422
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-71855
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass detection mechanisms.

The vulnerability exists due to incorrect comparison in the flow handling logic when processing packets that cause IPv4 and IPv6 flow hash collisions. A remote attacker can send specially crafted network traffic to bypass detection mechanisms.

This can occur when raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket line up, causing flow state from one IP family to be reused for the other.


Affected software

Suricata

How to mitigate CVE-2026-71855

Install security update from vendor's website.

Suricata - addressed in versions 7.0.17, 8.0.6

External References

Related Security Bulletins