<Vulnerability name="CVE-2026-45765">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-10T21:25:22</PublicDate>
    <Bugzilla id="2531990" url="https://bugzilla.redhat.com/show_bug.cgi?id=2531990" xml:lang="en:us">
Suricata: Suricata: Denial of Service via unbounded DNP3 reassembly
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-1284</CWE>
    <Details xml:lang="en:us" source="Mitre">
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted DNP3 traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable DNP3 (which is not enabled by default) if it is not needed, and/or define a limited `stream.reassembly.depth` (0 or absent is unlimited).
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Suricata. DNP3 reassembly could buffer data without sufficient parser-level bounds. A remote attacker sending crafted DNP3 traffic may cause Suricata to consume excessive memory, potentially resulting in a denial of service.
    </Details>
    <Statement xml:lang="en:us">
Unbounded memory allocation during DNP3 stream reassembly in Suricata allows remote, unauthenticated attackers to send crafted DNP3 packet streams, causing excessive memory consumption and triggering a daemon crash. Default Red Hat deployments processing untrusted network streams with DNP3 inspection active expose the monitoring service to denial-of-service vectors without explicit parser depth boundaries.
    </Statement>
    <Mitigation xml:lang="en:us">
Disable DNP3 parsing in the Suricata configuration file or configure a restricted maximum stream reassembly depth using the `stream.reassembly.depth` setting to cap memory utilization.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-45765
https://nvd.nist.gov/vuln/detail/CVE-2026-45765
https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
https://github.com/OISF/suricata/security/advisories/GHSA-m8x4-c78g-r4vj
https://redmine.openinfosecfoundation.org/issues/8460
    </References>
</Vulnerability>