Suricata DCERPC Buffering Inefficiency Leading to Performance Degradation Vulnerability

Vulnerability

A performance degradation vulnerability has been identified in Suricata, a network IDS, IPS, and NSM engine, prior to version 7.0.15. The issue arises from an inefficiency in DCERPC buffering, which can cause a significant processing cost and reduce the application's availability.

Impact

Exploitation of this vulnerability causes high processing costs, leading to a notable reduction in the application's availability.

Remediation

Users can upgrade to Suricata version 7.0.15 or 8 to address this vulnerability. Alternatively, the 'dcerpc' parser can be disabled as a temporary workaround.

Added: Apr 2, 2026, 4:09 PM
Updated: Apr 2, 2026, 4:09 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.7
remediation
8.3
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.