Always-Incorrect Control Flow Implementation in Suricata - #VU152934
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass LDAP application-layer inspection for an affected TCP flow.
The vulnerability exists due to incorrect control flow implementation in LDAP app-layer inspection when resynchronizing after a TCP reassembly gap. A remote attacker can send TCP traffic containing a reassembly gap followed by data that cannot immediately be parsed as a complete LDAP message to bypass LDAP application-layer inspection for an affected TCP flow.
Raw payload and stream inspection remain active, and UDP LDAP is unaffected.