Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22259

Опубликовано: 27 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
Версия до 7.0.14 (исключая)
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.3 (исключая)

EPSS

Процентиль: 15%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).

CVSS3: 7.5
debian
8 дней назад

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 ...

CVSS3: 7.5
fstec
27 дней назад

Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 15%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-400