PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45769 OISF CVE debrief

A vulnerability in Suricata, a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine, could allow an attacker to cause a denial of service by consuming excessive memory through repeated crafted UDP traffic. The issue is fixed in versions 7.0.16 and 8.0.5. This vulnerability affects network security monitoring and intrusion detection capabilities, requiring immediate attention from network defenders and administrators using Suricata to assess exposure and prioritize updates.

Vendor
OISF
Product
suricata
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-11
Advisory published
2026-09-10
Advisory updated
2026-09-11

Who should care

Network defenders and administrators using Suricata should assess exposure and prioritize updating to versions 7.0.16 or 8.0.5. This vulnerability affects network security monitoring and intrusion detection capabilities, requiring immediate attention from those responsible for maintaining Suricata deployments. Affected operators, platforms, and security teams should review and address this vulnerability to prevent potential denial-of-service attacks.

Why it matters

Defenders should care about this vulnerability as it could allow an attacker to cause a denial of service in Suricata, potentially affecting network security monitoring and intrusion detection capabilities. Network defenders and administrators using Suricata should assess exposure and prioritize updating to versions 7.0.16 or 8.0.5. The vulnerability requires verification of affected versions and remediation priority.

  • Denial of service through excessive memory consumption
  • Potential for repeated crafted UDP traffic to cause Suricata to consume excessive memory

Technical summary

The IKEv2 parser state in Suricata could grow without bounds while storing client transforms, potentially resulting in denial of service through repeated crafted UDP traffic. This issue arises from the parser's inability to limit the number of client transforms, allowing an attacker to cause excessive memory consumption. Network defenders and administrators should be aware of the potential for denial-of-service attacks and take steps to mitigate this vulnerability. The vulnerability is addressed in Suricata versions 7.0.16 and 8.0.5.

Defensive priority

Defenders should prioritize updating Suricata to versions 7.0.16 or 8.0.5 to prevent potential denial of service attacks.

Recommended defensive actions

  • Update Suricata to version 7.0.16 or 8.0.5
  • Disable IKE application-layer parsing if not needed
  • Use a rule to bypass IKE flows after the first packets
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability requires verification of affected versions and remediation priority. Network defenders should verify Suricata version deployments and assess potential exposure to this denial-of-service vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45769 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45769

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45769 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45769

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.