Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).
References
| Link | Resource |
|---|---|
| https://github.com/OISF/suricata/commit/50cac2e2465ca211eabfa156623e585e9037bb7e | Patch |
| https://github.com/OISF/suricata/commit/63225d5f8ef64cc65164c0bb1800730842d54942 | Patch |
| https://github.com/OISF/suricata/security/advisories/GHSA-878h-2x6v-84q9 | Patch Vendor Advisory |
| https://redmine.openinfosecfoundation.org/issues/8181 | Issue Tracking Permissions Required |
Configurations
Configuration 1 (hide)
|
History
30 Jan 2026, 20:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/OISF/suricata/commit/50cac2e2465ca211eabfa156623e585e9037bb7e - Patch | |
| References | () https://github.com/OISF/suricata/commit/63225d5f8ef64cc65164c0bb1800730842d54942 - Patch | |
| References | () https://github.com/OISF/suricata/security/advisories/GHSA-878h-2x6v-84q9 - Patch, Vendor Advisory | |
| References | () https://redmine.openinfosecfoundation.org/issues/8181 - Issue Tracking, Permissions Required | |
| CPE | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* | |
| First Time |
Oisf
Oisf suricata |
27 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-27 17:16
Updated : 2026-01-30 20:01
NVD link : CVE-2026-22259
Mitre link : CVE-2026-22259
CVE.ORG link : CVE-2026-22259
JSON object : View
Products Affected
oisf
- suricata
