CVE-2026-46352: Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented. Version 8.0.5 contains a fix. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Suricatato a version that resolves this vulnerability.Fixed in 8.0.5
Event History
Frequently Asked Questions
Which deployments are affected?
Suricata versions 8.0.0 through versions before 8.0.5 are affected. Version 8.0.5 contains the fix.
What traffic is required to trigger the issue?
The issue occurs when Suricata processes fragmented traffic carrying an encapsulated tunnel protocol whose payload is also fragmented. Exploitation does not require authentication or user interaction.
What is the operational impact of successful exploitation?
Processing the crafted traffic can cause Suricata's IP defragmentation code to deadlock, resulting in an availability impact.
What can be done if an upgrade is not immediately possible?
No known workarounds are available. Upgrade to Suricata 8.0.5 to obtain the fix.