7.5
CVE-2026-71855
- EPSS 0.31%
- Veröffentlicht 18.09.2026 20:25:58
- Zuletzt bearbeitet 28.09.2026 18:39:08
- Erkennungen
Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.243 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| security-advisories@github.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-697 Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
https://github.com/OISF/suricata/releases/tag/suricata-7.0.17
https://github.com/OISF/suricata/releases/tag/suricata-8.0.6
https://github.com/OISF/suricata/security/advisories/GHSA-fvwh-wjcq-2586
https://github.com/OISF/suricata/commit/181b3b2fdd1fe87e4534de4fc79e29a083ef125f
https://github.com/OISF/suricata/commit/4e2f23d031fbcfd72883bacd3d723c9874f23701
https://github.com/OISF/suricata/commit/bc41dcc854e24487d3786ce578a8a86a8350ab20
https://redmine.openinfosecfoundation.org/issues/8558