CVE-2026-57229

Description

A flaw was found in Suricata, a network Intrusion Detection System (IDS), Intrusion Prevention System (IPS), and Network Security Monitoring engine. The SMTP (Simple Mail Transfer Protocol) MIME (Multipurpose Internet Mail Extensions) parser does not fully reset its state when processing encapsulated messages. This allows an attacker to craft malicious emails that can bypass detection mechanisms, potentially leading to the evasion of security monitoring.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

To mitigate this issue, disable SMTP MIME decoding in Suricata's configuration. This action prevents the parser from processing `message/rfc822` encapsulations in a way that could lead to detection bypasses. Disabling this feature may affect the ability to inspect certain email content. Consult Suricata documentation for specific configuration instructions. A restart of the Suricata service may be required for changes to take effect.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Unexpected State

Frequently Asked Questions

Want to get errata notifications? Sign up here.