9.1
CVE-2026-57228
- EPSS 0.56%
- Veröffentlicht 18.09.2026 20:11:24
- Zuletzt bearbeitet 29.09.2026 12:47:52
- Erkennungen
Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape sequence is split across traffic chunks and the following chunk contains exactly one byte. Crafted SMTP traffic can trigger the out-of-bounds read and crash Suricata when decode-quoted-printable MIME decoding is enabled. This issue is fixed in version 7.0.17.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.456 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
|
| security-advisories@github.com | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://github.com/OISF/suricata/releases/tag/suricata-7.0.17
https://github.com/OISF/suricata/security/advisories/GHSA-qxm4-q7vx-7xj4
https://github.com/OISF/suricata/commit/19880f9d5bbe2b8f8e8867a577848dce2b532c86
https://redmine.openinfosecfoundation.org/issues/8608