CVE-2026-22258
While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable. DCERPC/TCP in the default configuration should not be vulnerable as the default stream depth is limited to 1MiB. Versions 8.0.3 and 7.0.14 contain a patch. Some workarounds are available. For DCERPC/UDP, disable the parser. For DCERPC/TCP, the `stream.reassembly.depth` setting will limit the amount of data that can be buffered. For DCERPC/SMB, the `stream.reassembly.depth` can be used as well, but is set to unlimited by default. Imposing a limit here may lead to loss of visibility in SMB.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-770
- Affected
- oisf/suricata
- Source
- security-advisories@github.com
References
- https://github.com/OISF/suricata/commit/39d8c302af3422a096b75474a4f295a754ec6a74Patch
- https://github.com/OISF/suricata/commit/f82a388d0283725cb76782cf64e8341cab370830Patch
- https://github.com/OISF/suricata/security/advisories/GHSA-289c-h599-3xcxPatch, Vendor Advisory
- https://redmine.openinfosecfoundation.org/issues/8182Issue Tracking, Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.