Improper Handling of Length Parameter Inconsistency in Suricata - #VU152929

 

Improper Handling of Length Parameter Inconsistency in Suricata - #VU152929

Published: September 30, 2026


Vulnerability identifier: #VU152929
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-130
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass PostgreSQL response inspection.

The vulnerability exists due to improper handling of length parameter inconsistency in the PostgreSQL response parser when processing malformed RowDescription or DataRow responses. A remote attacker can send a malformed PostgreSQL server response to bypass PostgreSQL response inspection.

Only deployments with PostgreSQL parsing enabled are affected. Raw stream inspection and packet forwarding continue.


Affected software

Suricata

Remediation

Install security update from vendor's website.

Suricata - update to 8.0.7

External References

Related Security Bulletins