CVE-2026-31932

Description

A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring (NSM) engine. An attacker can exploit an inefficiency in the Kerberos 5 (KRB5) buffering mechanism by sending specially crafted network traffic. This can lead to significant performance degradation, effectively causing a Denial of Service (DoS) for the affected system.

Statement

This Important flaw in Suricata, a network intrusion detection and prevention system, stems from an inefficiency in its Kerberos 5 (KRB5) buffering mechanism. An unauthenticated attacker can send specially crafted network traffic to a system running Suricata, leading to significant performance degradation and a denial of service. This affects Suricata deployments within Red Hat Community Projects.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.