medium · CVSS v3 5.9
CVE-2026-71855
Suricata versions prior to 7.0.17 and 8.0.6 incorrectly treat IPv4 and IPv6 flows as identical, allowing an attacker to reuse flow state acr
Overview
Suricata versions prior to 7.0.17 and 8.0.6 incorrectly treat IPv4 and IPv6 flows as identical, allowing an attacker to reuse flow state across IP families. This flaw can corrupt flowbit state, bypass detection rules, or create IP‑only bypasses. The issue is fixed in newer releases.
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equal without comparing the IP family when their raw address words, ports, protocol, VLAN, recursion level, live device, and hash bucket align. An IPv6 packet can therefore reuse IPv4 flow state or the reverse, causing incorrect flowbit state, detection bypass, or IP-only bypass. This issue is fixed in versions 8.0.6 and 7.0.17.
Impact
Confidentiality: attackers may bypass detection rules, allowing malicious traffic to go undetected. Integrity: corrupted flowbit state can produce false positives or negatives. Availability: mismanaged flow state may lead to resource exhaustion. Defenders: network security teams deploying Suricata IDS/IPS are directly impacted.
Remediation
Upgrade Suricata to at least 7.0.17 or 8.0.6. If an upgrade is not immediately possible, isolate IPv4 and IPv6 traffic to separate Suricata instances or disable shared flowbit state. Verify that configuration files do not share flow tables across IP families and monitor logs for anomalous flowbit behavior.
Risk context
The vulnerability has a medium severity (CVSS 5.9) and no EPSS data is available. While it does not allow direct exploitation, it can lead to detection bypass, so timely patching is advised.
Affected products
- Suricata 7.x
- Suricata 8.x
- Suricata 6.x
- Suricata 5.x
- Suricata 4.x
- Suricata 3.x
- Suricata 2.x
- Suricata 1.x
Scores
- Severity
- medium
- CVSS v2
- 5.4
- CVSS v3
- 5.9
- CVSS v4
- —
- EPSS
- —