Interpretation Conflict in Suricata - #VU152931
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass ssh.hassh* detection and cause hassh fields to be omitted from EVE output.
The vulnerability exists due to an interpretation conflict in Suricata's SSH hassh inspection parser when processing crafted SSH traffic containing an oversized incomplete KEXINIT record. A remote attacker can send a crafted SSH record to desynchronize parsing for one flow direction and bypass ssh.hassh* detection.
Only subsequent records in the affected flow direction are impacted.