7.5
CVE-2026-45766
- EPSS -
- Veröffentlicht 10.09.2026 21:26:39
- Zuletzt bearbeitet 16.09.2026 20:18:22
- Erkennungen
Suricata nfs: unbounded stateful structures can lead to resource exhaustion
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS application-layer parsing if it is not needed.
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
https://github.com/OISF/suricata/security/advisories/GHSA-jqr4-ch38-wvm6
https://redmine.openinfosecfoundation.org/issues/8418