CVE-2026-45766: Suricata nfs: unbounded stateful structures can lead to resource exhaustion
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 contain a fix. As a workaround, disable NFS application-layer parsing if it is not needed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.16 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.5 - Configuration
As a workaround, disable NFS application-layer parsing if it is not needed, since crafted NFS traffic may cause Suricata to consume excessive memory.
Suricata (NFS parser) NFS application-layer parsing = disabled
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Suricata deployments running a version earlier than 7.0.16 or 8.0.5 are affected when NFS application-layer parsing is enabled and they process crafted NFS traffic.
What does an attacker need to exploit it?
An attacker only needs to send crafted NFS traffic to a vulnerable Suricata instance. No privileges or user interaction are required.
What can be done if upgrading is not immediately possible?
Disable NFS application-layer parsing if it is not needed. This removes the vulnerable parsing path but also prevents Suricata from performing application-layer parsing of NFS traffic.
How can I determine whether the issue has been fixed?
Verify the deployed Suricata version. Versions 7.0.16 and 8.0.5 contain the fix.