Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-57229
Suricata Schwachstellenanalyse und -minderung

Überblick

CVE-2026-57229 is an SMTP/MIME parsing vulnerability in Suricata that allows detection bypass via incomplete state reset. Affecting Suricata versions 8.0.0 through 8.0.5, the flaw enables crafted SMTP MIME messages to cause outer MIME part encoding or filename state to carry into an inner message, allowing attackers to evade network detections. It was published on July 21, 2026, and patched in Suricata 8.0.6. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technische Details

The root cause is an improper initialization issue (CWE-665) in Suricata's SMTP MIME parser, where the parser state is not fully reset when processing Content-Type: message/rfc822 encapsulation. This allows encoding or filename state from an outer MIME part to bleed into an inner message during parsing. An unauthenticated, remote attacker can exploit this by sending a specially crafted SMTP MIME message over the network, requiring no privileges or user interaction. The fix is tracked in the Suricata commit c0215c7e175b0000ef8450928dd1f3453c48379b (GitHub Advisory, GitHub Commit).

Aufprall

Successful exploitation allows an attacker to evade Suricata-based network detections that rely on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. The primary impact is an integrity loss — specifically, the bypass of security monitoring and detection rules — with no direct confidentiality or availability impact. This could allow malicious email attachments or URLs to pass through Suricata-protected network segments undetected (GitHub Advisory).

Ausnutzbarkeit

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-57229. The CVE was reserved and the advisory published on July 21, 2026, with credit given to researcher Changcheng Wu (@Clouditera). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no EPSS score data is currently available (GitHub Advisory).

Ausnutzungsschritte

  1. Craft a malicious SMTP MIME message: Construct an email with a Content-Type: message/rfc822 encapsulation where the outer MIME part contains encoding or filename state (e.g., a specific Content-Transfer-Encoding or Content-Disposition: filename) that should not apply to the inner message.
  2. Embed malicious content in the inner message: Place a malicious file attachment or URL in the inner message/rfc822 part that would normally be detected by Suricata rules targeting file.data, file.name, or extracted URLs.
  3. Deliver the message through a Suricata-monitored network path: Send the crafted email via SMTP through a network segment monitored by a vulnerable Suricata instance (versions 8.0.0–8.0.5) with SMTP MIME decoding enabled.
  4. Trigger the state bleed: Suricata's MIME parser fails to fully reset state between the outer and inner MIME parts, causing the inner message's content to be parsed under the outer part's context, causing detection rules to misclassify or skip the malicious content.
  5. Achieve detection bypass: The malicious payload (file or URL) passes through Suricata without triggering relevant signatures, allowing downstream delivery to the target (GitHub Advisory).

Indikatoren für Kompromittierung

  • Network: SMTP traffic containing nested Content-Type: message/rfc822 MIME structures with unusual or mismatched Content-Transfer-Encoding or Content-Disposition headers in outer versus inner parts.
  • Logs: Suricata logs showing SMTP sessions where MIME decoding produced unexpected or absent file extraction events for messages with message/rfc822 encapsulation; absence of expected alerts for known-malicious file names or URLs in such messages.
  • Process/Detection: Gaps in Suricata file.data or file.name rule alerts for SMTP traffic that contains nested MIME structures, particularly when compared against mail server logs showing attachment delivery.

Risikominderung und Problemumgehungen

Upgrade to Suricata 8.0.6 or later, which contains the fix for the incomplete MIME state reset. The official advisory confirms no workarounds are available for this vulnerability. Organizations running Suricata 8.0.0 through 8.0.5 with SMTP MIME decoding enabled should prioritize this upgrade (GitHub Advisory, Suricata Release).

Reaktionen der Community

The vulnerability was credited to researcher Changcheng Wu (@Clouditera), and the advisory was published by Suricata maintainer jasonish on GitHub. The Suricata project released versions 8.0.6 and 7.0.17 simultaneously to address multiple issues, with the release announced on the official Suricata forum and blog. OpenSUSE and other Linux distributions issued security update announcements for their Suricata packages following the release (Suricata Forum, Suricata Release, OpenSUSE Advisory).

Zusätzliche Ressourcen

Status der Linux-Distribution-Korrektur

Verfügbarkeit von Korrekturen in den wichtigsten Linux-Distributionen und deren Versionen.

Debian

Behoben

sid

suricata: 1:8.0.6-1

Behoben

trixie

suricata

Betroffen

Ubuntu

Unbekannt

bionic (esm-apps)

suricata

Unbekannt

devel

suricata

Nicht betroffen

jammy

suricata

Unbekannt

jammy (esm-apps)

suricata

Unbekannt

noble

suricata

Unbekannt

noble (esm-apps)

suricata

Unbekannt

resolute

suricata

Unbekannt

resolute (esm-apps)

suricata

Unbekannt

QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Suricata Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-57228HIGH8.2
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57227HIGH7.5
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57223HIGH7
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57229MEDIUM5.3
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026
CVE-2026-57225LOW3.3
  • Suricata logoSuricata
  • suricata
NeinJaSep 18, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement