CVE-2026-31931
Suricata vulnerability analysis and mitigation

Overview

CVE-2026-31931 is a NULL pointer dereference vulnerability in Suricata, the open-source network IDS, IPS, and NSM engine. When the tls.alpn rule keyword is used in detection rules, Suricata can crash due to improper handling of a NULL pointer, resulting in a denial of service. The vulnerability affects Suricata versions 8.0.0 through 8.0.3 and was patched in version 8.0.4, released on March 17, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is a NULL pointer dereference (CWE-476) in Suricata's handling of the tls.alpn rule keyword, which is used to match the TLS Application-Layer Protocol Negotiation extension in network traffic. When a rule using this keyword is evaluated against certain network traffic, Suricata dereferences a pointer that is unexpectedly NULL, causing an application crash. The vulnerability is remotely exploitable with no authentication, privileges, or user interaction required — an attacker simply needs to send crafted or opportunistic network traffic that triggers evaluation of a tls.alpn-based rule. The issue was discovered by OSS-Fuzz (GitHub Advisory).

Impact

Successful exploitation causes Suricata to crash, resulting in a complete loss of availability for the IDS/IPS/NSM monitoring function. This means network traffic is no longer inspected or blocked during the outage, potentially leaving the protected network exposed to other threats. There is no impact on confidentiality or data integrity, as the vulnerability only affects availability (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.046%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that the target Suricata instance has at least one active rule using the tls.alpn keyword; notably, no common rulesets are known to use this keyword by default (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify network segments monitored by Suricata 8.0.0–8.0.3 instances that have rules using the tls.alpn keyword active.
  2. Craft TLS traffic: Generate TLS ClientHello or ServerHello packets containing an ALPN extension with values designed to trigger the NULL dereference condition during rule evaluation.
  3. Transmit traffic: Send the crafted TLS packets across the monitored network segment so they are captured and processed by the vulnerable Suricata instance.
  4. Trigger crash: Suricata evaluates the tls.alpn rule against the packet, dereferences a NULL pointer, and crashes — disabling IDS/IPS/NSM monitoring for the duration of the outage (GitHub Advisory).

Indicators of compromise

  • Logs: Suricata process crash logs or core dump files generated around the time of suspicious TLS traffic; system logs (e.g., syslog, journald) showing unexpected Suricata process termination.
  • Process: Suricata process absent or repeatedly restarting (if supervised by systemd or similar); watchdog or monitoring alerts for Suricata service unavailability.
  • Network: Unusual or malformed TLS ClientHello/ServerHello packets with ALPN extensions targeting monitored interfaces, particularly from external or untrusted sources.

Mitigation and workarounds

Upgrade Suricata to version 8.0.4 or later, which contains the official patch for this vulnerability (GitHub Advisory, Suricata Release). As a temporary workaround for organizations unable to upgrade immediately, disable or remove any IDS/IPS rules that use the tls.alpn keyword. The advisory notes that no common rulesets (e.g., Emerging Threats, Suricata default rules) use this keyword, so the workaround impact should be minimal for most deployments (GitHub Advisory).

Community reactions

The vulnerability was discovered by OSS-Fuzz, Google's continuous fuzzing service for open-source software, and responsibly disclosed to the OISF team. The Suricata project published the advisory and patched release promptly. Coverage appeared on security aggregators and community forums, including the Suricata community forum and openSUSE security announcements, but no significant controversy or widespread concern was noted given the limited real-world rule usage of the affected keyword (Suricata Forum, openSUSE).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

suricata: 1:8.0.4-1

Fixed

trixie

suricata

Fixed

Ubuntu

Unknown

bionic (esm-apps)

suricata

Unknown

devel

suricata

Unknown

jammy

suricata

Unknown

jammy (esm-apps)

suricata

Unknown

noble

suricata

Unknown

noble (esm-apps)

suricata

Unknown

resolute

suricata

Unknown

resolute (esm-apps)

suricata

Unknown

Alpine

Fixed

edge

suricata: 8.0.6-r0

Fixed

SourceThis report was generated using AI

Related Suricata vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-31937HIGH7.5
  • Suricata logoSuricata
  • suricata
NoYesApr 02, 2026
CVE-2026-31935HIGH7.5
  • Suricata logoSuricata
  • suricata
NoYesApr 02, 2026
CVE-2026-31934HIGH7.5
  • Suricata logoSuricata
  • suricata
NoYesApr 02, 2026
CVE-2026-31933HIGH7.5
  • Suricata logoSuricata
  • cpe:2.3:a:oisf:suricata
NoYesApr 02, 2026
CVE-2026-45763MEDIUM5.9
  • Suricata logoSuricata
  • cpe:2.3:a:oisf:suricata
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management