Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-57227
Suricata Schwachstellenanalyse und -minderung

Überblick

CVE-2026-57227 is a denial-of-service vulnerability in OISF Suricata's MQTT parser caused by unbounded resource consumption from repeated PUBREC and PUBREL messages. It affects Suricata versions 7.x prior to 7.0.17 and 8.x prior to 8.0.6. The vulnerability was published on July 21, 2026, with patches released in Suricata 7.0.17 and 8.0.6. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technische Details

The root cause is improper resource management in Suricata's MQTT application-layer parser, classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Allocation of Resources Without Limits or Throttling). The parser appends repeated MQTT PUBREC or PUBREL messages to a transaction without enforcing any upper bound on the number of such messages, allowing an attacker to craft malicious MQTT traffic that causes excessive memory or CPU consumption. Exploitation requires no authentication, no user interaction, and is achievable remotely over the network, making it particularly dangerous in remote IDS/IPS deployment scenarios (GitHub Advisory). Patches are available in commits for both the 7.0.17 and 8.0.6 release branches (Suricata 7.0.17 Commit, Suricata 8.0.6 Commit).

Aufprall

Successful exploitation causes Suricata to enter an infinite loop or crash, resulting in a complete loss of availability for the IDS/IPS sensor. Because Suricata is a network security monitoring tool, its disruption can blind defenders to ongoing attacks, effectively neutralizing network-level threat detection. There is no impact on confidentiality or integrity — the sole consequence is availability loss (GitHub Advisory).

Ausnutzbarkeit

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of writing. The vulnerability is unauthenticated and remotely exploitable with low attack complexity, meaning any attacker capable of sending crafted MQTT traffic to a monitored network segment can trigger it. The CVE status was listed as "Reserved" at the time of Feedly ingestion, and no CISA KEV listing or threat actor attribution has been identified (GitHub Advisory, Feedly).

Ausnutzungsschritte

  1. Reconnaissance: Identify network segments monitored by Suricata 7.x < 7.0.17 or 8.x < 8.0.6 with MQTT inspection enabled (default configuration).
  2. Craft malicious MQTT traffic: Construct a sequence of MQTT PUBREC and PUBREL messages that are repeatedly sent within a single MQTT session or transaction, without a corresponding PUBCOMP to close the flow.
  3. Transmit traffic to monitored segment: Send the crafted MQTT packet stream across the network interface being monitored by the vulnerable Suricata instance. No direct access to the Suricata host is required — only the ability to inject traffic into the monitored network.
  4. Trigger resource exhaustion: Suricata's MQTT parser appends each PUBREC/PUBREL to the transaction list without bound, consuming increasing memory or CPU until the process slows significantly or crashes, disabling IDS/IPS functionality (GitHub Advisory).

Indikatoren für Kompromittierung

  • Process: Suricata process exhibiting abnormally high CPU usage or memory growth, potentially leading to process crash or restart.
  • Logs: Suricata logs showing a high volume of MQTT transactions or parser errors; unexpected Suricata service restarts recorded in system logs (e.g., journalctl -u suricata).
  • Network: Unusual MQTT traffic patterns on monitored interfaces featuring repeated PUBREC/PUBREL message sequences without corresponding PUBCOMP messages, particularly from external or untrusted sources.

Risikominderung und Problemumgehungen

Upgrade Suricata to version 7.0.17 or 8.0.6, which enforce bounds on PUBREC/PUBREL message appending in the MQTT parser (GitHub Advisory). As a temporary workaround for environments where MQTT inspection is not required, disable the MQTT app-layer parser by setting app-layer.protocols.mqtt.enabled: no in the Suricata configuration file. Organizations should prioritize patching given the zero-privilege, network-accessible nature of the vulnerability (Suricata Release).

Reaktionen der Community

The Suricata project announced the releases of 7.0.17 and 8.0.6 via their official forum and blog, explicitly referencing this and related security fixes (Suricata Forum, Suricata Blog). OpenSUSE and SUSE issued security announcements for updated Suricata packages addressing this CVE (OpenSUSE Security). Tenable published Nessus detection plugins (IDs 330413 and 344723) to identify vulnerable Suricata installations (Tenable).

Zusätzliche Ressourcen

Status der Linux-Distribution-Korrektur

Verfügbarkeit von Korrekturen in den wichtigsten Linux-Distributionen und deren Versionen.

Debian

Behoben

sid

suricata: 1:8.0.6-1

Behoben

trixie

suricata

Betroffen

Ubuntu

Unbekannt

bionic (esm-apps)

suricata

Unbekannt

devel

suricata

Nicht betroffen

jammy

suricata

Unbekannt

jammy (esm-apps)

suricata

Unbekannt

noble

suricata

Unbekannt

noble (esm-apps)

suricata

Unbekannt

resolute

suricata

Unbekannt

resolute (esm-apps)

suricata

Unbekannt

QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Suricata Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-57228HIGH8.2
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57227HIGH7.5
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57223HIGH7
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57229MEDIUM5.3
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57225LOW3.3
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement