{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-03T10:37:04.699","vulnerabilities":[{"cve":{"id":"CVE-2026-22258","sourceIdentifier":"security-advisories@github.com","published":"2026-01-27T17:16:12.253","lastModified":"2026-06-17T10:19:39.013","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable. DCERPC/TCP in the default configuration should not be vulnerable as the default stream depth is limited to 1MiB. Versions 8.0.3 and 7.0.14 contain a patch. Some workarounds are available. For DCERPC/UDP, disable the parser. For DCERPC/TCP, the `stream.reassembly.depth` setting will limit the amount of data that can be buffered. For DCERPC/SMB, the `stream.reassembly.depth` can be used as well, but is set to unlimited by default. Imposing a limit here may lead to loss of visibility in SMB."},{"lang":"es","value":"Suricata es un motor de IDS, IPS y NSM de red. Antes de las versiones 8.0.3 y 7.0.14, el tráfico DCERPC manipulado puede hacer que Suricata expanda un búfer sin límites, lo que lleva al agotamiento de la memoria y a la terminación del proceso. Aunque se informó para DCERPC sobre UDP, se cree que DCERPC sobre TCP y SMB también son vulnerables. DCERPC/TCP en la configuración predeterminada no debería ser vulnerable, ya que la profundidad de flujo predeterminada está limitada a 1 MiB. Las versiones 8.0.3 y 7.0.14 contienen un parche. Algunas soluciones alternativas están disponibles. Para DCERPC/UDP, deshabilite el analizador. Para DCERPC/TCP, la configuración 'stream.reassembly.depth' limitará la cantidad de datos que se pueden almacenar en búfer. Para DCERPC/SMB, también se puede usar 'stream.reassembly.depth', pero está configurado como ilimitado por defecto. Imponer un límite aquí puede llevar a la pérdida de visibilidad en SMB."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"OISF","product":"suricata","versions":[{"version":"< 7.0.14","status":"affected"},{"version":">= 8.0.0, < 8.0.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-27T18:26:50.259731Z","id":"CVE-2026-22258","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.14","matchCriteriaId":"5302B0F0-AF2D-4140-BC66-9186EF7E455D"},{"vulnerable":true,"criteria":"cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.3","matchCriteriaId":"E7DA8362-52A2-4ACC-83F7-CA2E77AE89C6"}]}]}],"references":[{"url":"https://github.com/OISF/suricata/commit/39d8c302af3422a096b75474a4f295a754ec6a74","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/OISF/suricata/commit/f82a388d0283725cb76782cf64e8341cab370830","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/OISF/suricata/security/advisories/GHSA-289c-h599-3xcx","source":"security-advisories@github.com","tags":["Patch","Vendor Advisory"]},{"url":"https://redmine.openinfosecfoundation.org/issues/8182","source":"security-advisories@github.com","tags":["Issue Tracking","Permissions Required"]}]}}]}