CVE-2026-45769
Description
A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring engine. A remote attacker can exploit this vulnerability by sending repeated crafted User Datagram Protocol (UDP) traffic to the IKEv2 parser. This can cause the Suricata engine to consume excessive memory, leading to a denial of service (DoS) for the affected system.
Statement
The vulnerability in Suricata, rated as Important, allows a remote attacker to cause a denial of service by sending specially crafted UDP traffic. This can lead to unbounded memory growth within the IKEv2 parser, consuming excessive resources and potentially crashing the Suricata engine. This impact is significant in environments where Suricata is deployed for network intrusion detection or prevention.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.