Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-57228
Suricata Schwachstellenanalyse und -minderung

Überblick

CVE-2026-57228 is a heap out-of-bounds read vulnerability in Suricata's SMTP MIME quoted-printable decoder, affecting versions 7.0.13 through prior to 7.0.17. The flaw can cause Suricata to crash or consume excessive resources when processing crafted network traffic, resulting in a denial of service. It was disclosed on July 21, 2026, and patched in Suricata 7.0.17. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory).

Technische Details

The root cause is an out-of-bounds read (CWE-125) in Suricata's SMTP MIME quoted-printable decoder. Specifically, when a quoted-printable escape sequence is split across two traffic chunks and the subsequent chunk is only one byte long, the decoder reads one byte past the end of a heap-allocated buffer. This flaw is remotely exploitable with no authentication or user interaction required — an attacker simply needs to send crafted SMTP traffic that triggers the boundary condition. The fix is tracked in commit 19880f9d5bbe2b8f8e8867a577848dce2b532c86 targeting the 7.0.17 release (GitHub Advisory, GitHub Commit).

Aufprall

Successful exploitation can crash the Suricata IDS/IPS process, disabling network traffic inspection and alerting capabilities. Because Suricata is commonly deployed as a network security monitor or inline IPS, crashing it could allow subsequent malicious traffic to pass undetected. There is also a limited confidentiality impact, as the out-of-bounds read may expose one byte of adjacent heap memory. Availability is the primary concern, as the crash effectively blinds the affected network segment to threats (GitHub Advisory).

Ausnutzbarkeit

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The vulnerability was discovered by Trail of Bits in collaboration with Anthropic and responsibly disclosed. The CVE status was listed as "Reserved" at the time of Feedly ingestion, with Nessus detection plugins (IDs 330414 and 344766) subsequently published to identify vulnerable systems. There is no current CISA KEV catalog listing for this CVE (GitHub Advisory, Tenable).

Ausnutzungsschritte

  1. Reconnaissance: Identify network segments monitored by Suricata 7.0.13–7.0.16 (e.g., by observing IDS alert patterns or banner information from exposed management interfaces).
  2. Craft malicious SMTP traffic: Construct an SMTP message containing a MIME body encoded in quoted-printable format, where a quoted-printable escape sequence (e.g., =XX) is deliberately split across two TCP segments or reassembly chunks.
  3. Ensure the second chunk is exactly one byte: The triggering condition requires the chunk following the split escape sequence to be only one byte long, causing the decoder to read one byte beyond the heap buffer boundary.
  4. Transmit the crafted traffic: Send the malformed SMTP session through the network segment monitored by the vulnerable Suricata instance.
  5. Achieve denial of service: The out-of-bounds read triggers a crash of the Suricata process, disabling IDS/IPS inspection on the affected segment (GitHub Advisory).

Indikatoren für Kompromittierung

  • Process: Unexpected termination or crash of the suricata process; core dump files generated in the Suricata working directory.
  • Logs: Suricata error logs (/var/log/suricata/suricata.log) showing segmentation faults or memory access errors related to MIME/SMTP processing; entries referencing the quoted-printable decoder.
  • Network: Unusual SMTP sessions with MIME bodies where quoted-printable escape sequences are split across very small TCP segments (particularly a one-byte second segment); repeated SMTP connections from the same source triggering Suricata restarts.
  • File System: Presence of core dump files (e.g., core.*) in the Suricata run directory following unexpected process termination (GitHub Advisory).

Risikominderung und Problemumgehungen

Upgrade Suricata to version 7.0.17 or later, which contains the patch for this vulnerability. As an immediate workaround without upgrading, set app-layer.protocols.smtp.mime.decode-quoted-printable: no in suricata.yaml to disable the vulnerable decoder. Organizations running Suricata 7.0.13 through 7.0.16 in IPS (inline) mode should prioritize patching, as a crash in this mode removes active traffic blocking (GitHub Advisory, Suricata Release).

Reaktionen der Community

The vulnerability was credited to Trail of Bits in collaboration with Anthropic, reflecting the growing use of AI-assisted security research. The Suricata project released versions 7.0.17 and 8.0.6 simultaneously to address multiple security issues. openSUSE and SUSE issued security announcements for their Suricata packages, and Tenable published Nessus detection plugins shortly after disclosure (openSUSE Advisory, Suricata Release, Tenable).

Zusätzliche Ressourcen

Status der Linux-Distribution-Korrektur

Verfügbarkeit von Korrekturen in den wichtigsten Linux-Distributionen und deren Versionen.

Debian

Behoben

sid

suricata: 1:8.0.1-1

Behoben

trixie

suricata

Betroffen

Ubuntu

Unbekannt

bionic (esm-apps)

suricata

Unbekannt

devel

suricata

Nicht betroffen

jammy

suricata

Unbekannt

jammy (esm-apps)

suricata

Unbekannt

noble

suricata

Unbekannt

noble (esm-apps)

suricata

Unbekannt

resolute

suricata

Nicht betroffen

resolute (esm-apps)

suricata

Nicht betroffen

QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Suricata Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-57228HIGH8.2
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57227HIGH7.5
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57223HIGH7
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57229MEDIUM5.3
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57225LOW3.3
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement