CVE-2026-45768
Description
A flaw was found in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine. The LDAP (Lightweight Directory Access Protocol) transaction state could store an unbounded number of responses. A remote attacker could send crafted UDP (User Datagram Protocol) traffic, causing Suricata to consume excessive memory. This could lead to a denial of service, making the system unavailable.
Statement
This Important denial of service flaw in Suricata, which could lead to excessive memory consumption due to unbounded LDAP responses, does not affect Red Hat products. The vulnerable versions of Suricata (8.0.0 through 8.0.4) are not shipped in Red Hat Enterprise Linux or its derivatives.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.