CVE-2026-31937: Suricata dcerpc: quadratic complexity in dcerpc buffering
Published Apr 2, 2026
·Updated
Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.
Affected Software
1 affected component
OISF Suricata<7.0.15
Event History
Apr 2, 2026
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31937?
CVE-2026-31937 has a moderate severity rating due to its potential to cause performance degradation in Suricata.
2
How do I fix CVE-2026-31937?
To fix CVE-2026-31937, upgrade to Suricata version 7.0.15 or later.
3
What software is affected by CVE-2026-31937?
CVE-2026-31937 affects Suricata versions prior to 7.0.15.
4
What is the issue caused by CVE-2026-31937?
CVE-2026-31937 can lead to quadratic complexity in DCERPC buffering, impacting the performance of the system.
5
When was CVE-2026-31937 published?
CVE-2026-31937 was published as part of the security advisories addressing vulnerabilities in Suricata.