Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57227

Опубликовано: 18 сент. 2026
Источник: debian
EPSS Низкий

Описание

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or denial of service. This issue is fixed in versions 8.0.6 and 7.0.17.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:8.0.6-1package

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-7h2h-hpj2-9w6p

  • https://redmine.openinfosecfoundation.org/issues/8672 (suricata-7.0.17)

  • https://redmine.openinfosecfoundation.org/issues/8653 (suricata-8.0.6)

  • https://github.com/OISF/suricata/commit/5cde93dea38533c9b225128ba9d54955997dc273 (suricata-7.0.17)

  • https://github.com/OISF/suricata/commit/c03666d261256df5a2d1f5800872da8a5addf6a5 (suricata-8.0.6)

EPSS

Процентиль: 34%
0.00397
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 дней назад

[mqtt: unbounded number of messages per tx]

CVSS3: 7.5
nvd
3 дня назад

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or denial of service. This issue is fixed in versions 8.0.6 and 7.0.17.

EPSS

Процентиль: 34%
0.00397
Низкий