PatchSiren cyber security CVE debrief
CVE-2026-46352 OISF CVE debrief
A deadlock condition exists in Suricata's IP defragmentation code when processing fragmented traffic with an encapsulated tunnel protocol whose payload is also fragmented, affecting versions 8.0.0 through 8.0.4. This issue is fixed in version 8.0.5. The vulnerability can cause network service disruption, and defenders should assess their exposure and prioritize updating to version 8.0.5 or later. The issue is related to the handling of fragmented traffic, and the fix addresses this specific condition.
- Vendor
- OISF
- Product
- suricata
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-28
Who should care
Network defenders and security teams using Suricata for network security monitoring and intrusion detection should assess their exposure and prioritize updating to version 8.0.5 or later. This is crucial to prevent potential network service disruption due to the deadlock condition in the IP defragmentation code. They should also review and adjust network configurations to minimize exposure and monitor Suricata logs for potential issues.
Why it matters
A deadlock condition in Suricata's IP defragmentation code can cause network service disruption. Defenders should assess exposure, verify current version, and prioritize updating to version 8.0.5 or later.
- Potential network service disruption due to deadlock condition
- Need for verification of current Suricata version and exposure
- Priority for updating to fixed version 8.0.5
- Potential impact on network security monitoring and intrusion detection capabilities
Technical summary
The Suricata network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine has a deadlock condition in its IP defragmentation code. This occurs when processing fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented, affecting versions 8.0.0 through 8.0.4. The issue can cause network service disruption, and defenders should assess their exposure and prioritize updating to version 8.0.5 or later. The fix addresses this specific condition and is available in version 8.0.5.
Defensive priority
Defenders should prioritize updating to Suricata version 8.0.5 or later to address the deadlock condition in the IP defragmentation code.
Recommended defensive actions
- Update to Suricata version 8.0.5 or later
- Review and adjust network configurations to minimize exposure
- Monitor Suricata logs for potential issues
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- evidenceNotes
- whoShouldCare
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. Vendor advisories are available for Suricata versions 8.0.5 and 7.0.16.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46352 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46352
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46352 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46352
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://forum.suricata.io/t/suricata-8-0-5-and-7-0-16-released/6315
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/OISF/suricata/security/advisories/GHSA-rc34-46x6-mxxm
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://redmine.openinfosecfoundation.org/issues/8550
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.