CVE-2026-45766

Description

A flaw was found in Suricata, a network Intrusion Detection System. Insufficiently bounded Network File System (NFS) parser state structures can be exploited by a remote attacker sending crafted NFS traffic. This can cause Suricata to consume excessive memory, leading to a denial of service.

Statement

An Important denial of service flaw exists in Suricata due to unbounded NFS parser state structures, allowing crafted NFS traffic to consume excessive memory. While Suricata in Red Hat products is currently not affected, environments with enabled NFS application-layer parsing could be at risk.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.