Incorrect Comparison in Suricata - CVE-2026-71855
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass detection mechanisms.
The vulnerability exists due to incorrect comparison in the flow handling logic when processing packets that cause IPv4 and IPv6 flow hash collisions. A remote attacker can send specially crafted network traffic to bypass detection mechanisms.
This can occur when raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket line up, causing flow state from one IP family to be reused for the other.