CVE-2026-22259: Suricata dnp3: unbounded transaction growth
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22259?
CVE-2026-22259 has a severity rating that indicates it can lead to significant memory consumption issues in Suricata, potentially impacting its performance.
How do I fix CVE-2026-22259?
To fix CVE-2026-22259, upgrade Suricata to version 8.0.3 or later, or version 7.0.14 or later.
What systems are affected by CVE-2026-22259?
CVE-2026-22259 affects Suricata versions prior to 8.0.3 and 7.0.14.
What are the risks associated with CVE-2026-22259?
The risks associated with CVE-2026-22259 include potential denial of service due to excessive memory consumption when processing DNP3 traffic.
Is a patch available for CVE-2026-22259?
Yes, patches addressing CVE-2026-22259 are included in Suricata versions 8.0.3 and 7.0.14.