Interpretation Conflict in Suricata - #VU152931

 

Interpretation Conflict in Suricata - #VU152931

Published: September 30, 2026


Vulnerability identifier: #VU152931
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-436
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass ssh.hassh* detection and cause hassh fields to be omitted from EVE output.

The vulnerability exists due to an interpretation conflict in Suricata's SSH hassh inspection parser when processing crafted SSH traffic containing an oversized incomplete KEXINIT record. A remote attacker can send a crafted SSH record to desynchronize parsing for one flow direction and bypass ssh.hassh* detection.

Only subsequent records in the affected flow direction are impacted.


Affected software

Suricata

Remediation

Install security update from vendor's website.

Suricata - update to 8.0.7

External References

Related Security Bulletins