Executive brief
Suricata is a widely-deployed open-source network security monitoring engine used to detect and prevent network-based threats. A vulnerability in its NFS protocol parser allows attackers to craft malicious NFS traffic that causes excessive memory consumption, potentially crashing the security system and causing denial of service. Organizations relying on Suricata for network intrusion detection would lose visibility into malicious traffic during an attack.
Technical details
The vulnerability exists in Suricata's NFS application-layer parser, where certain state structures lack proper bounds checking (CWE-400, CWE-770). Attackers can send crafted NFS traffic over the network without authentication to trigger unbounded memory allocation in these stateful parser structures. This results in memory exhaustion and denial of service, causing Suricata to become unresponsive or crash. The attack requires only network reachability to the Suricata instance and no special privileges or user interaction. Patches are available in Suricata 7.0.16 and 8.0.5; a workaround is to disable NFS application-layer parsing if not required.
Affected products
- OISF Suricata before 7.0.16 and before 8.0.5
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched: Versions 7.0.16 and 8.0.5 released