CVE-2026-45769

    Dashboard / Vulnerabilities / CVE-2026-45769

    CVE-2026-45769

    Published: 10 Sept 2026Last Modified: 12 Sept 2026

    Summary: ikev2: unbounded client transform storage can lead to resource exhaustion

    Details: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeated crafted UDP traffic may cause Suricata to consume excessive memory, potentially resulting in denial of service. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Disable IKE application-layer parsing if it is not needed. Alternatively, use a rule to bypass ike flows after the first packets like `alert ike any any -> any any (sid: 2; flow.pkts_toserver: > 256; bypass; noalert;)`.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 9956286fb89f9cad9e9f95b99dc751f8666617b7

    Affected versions

    suricata-8.0.4
    suricata-8.0.3
    suricata-8.0.2
    suricata-8.0.1
    suricata-8.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-45769 | CVE-DB