Unchecked Return Value in Suricata - #VU152935
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass the configured app-layer error exception policy.
The vulnerability exists due to an unchecked return value in the IKEv1 parser when processing crafted IKEv1 traffic. A remote attacker can send a malformed IKEv1 datagram to bypass the configured app-layer error exception policy.
The bypass is limited to the malformed datagram or flow; later valid IKE datagrams and raw packet or payload inspection remain available.