Untriaged
Permalink
CVE-2026-31932
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Suricata krb5: quadratic complexity in krb5 buffering
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.
References
-
https://github.com/OISF/suricata/security/advisories/GHSA-rp9m-jcpw-hggr x_refsource_CONFIRM
-
https://redmine.openinfosecfoundation.org/issues/8305 x_refsource_MISC
Affected products
suricata
- ==>= 8.0.0, < 8.0.4
- ==< 7.0.15
Package maintainers
-
@magenbluten magenbluten <magenbluten@codemonkey.cc>